Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BackupPC ClientNameAlias()函数安全绕过漏洞
Vulnerability Description
当SSH keys和Rsync在一个多用户的环境下被使用时,BackupPC 3.1.0版本中的CgiUserConfigEdit没有限制来自ClientNameAlias函数的用户,这使得远程认证用户可以通过先修改ClientNameAlias来匹配另一个系统,然后再初始化一个文件备份或重新储存,从而实现读取和写敏感文件。
CVSS Information
N/A
Vulnerability Type
N/A