Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vulnerability in API endpoint: /api/<method> that can result in Task metadata such as task name, id, parameter, etc. will be leaked to unauthorized users. This attack appear to be exploitable via The victim must visit a specially crafted webpage from the network where their Luigi server is accessible.. This vulnerability appears to have been fixed in 2.8.0 and later.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Luigi 跨站请求伪造漏洞
Vulnerability Description
Luigi是一款用于构建批处理作业管道的Python包,它支持依赖项解析、工作流管理、可视化和命令行集成等。 Luigi 2.8.0之前版本中的API端点:/api/<method>存在跨站请求伪造漏洞。远程攻击者可借助特制的网页利用该漏洞获取Task元数据,例如:任务名、ID、参数。
CVSS Information
N/A
Vulnerability Type
N/A