Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RSyslog '$AllowedSender' Configuration Directive 安全绕过漏洞
Vulnerability Description
Rsyslog 是一个syslogd 的多线程增强软件。 rsyslog 3.12.1至3.20.0, 4.1.0,以及4.1.1版本的ACL处理不能服从$AllowedSender的指示,这会允许远程攻击者绕过预设访问限制,骗取登陆信息或创建大量的虚假信息。
CVSS Information
N/A
Vulnerability Type
N/A