PlaceOs Authentication Service是一个 PlaceOs 身份验证服务和 Api 看门人。 PlaceOs Authentication Service 存在输入验证错误漏洞,该漏洞源于1.29.10.0 版本之前的 PlaceOS 身份验证服务允许 app/controllers/auth/sessions_controller.rb 打开重定向。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41826.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23446 | 7.5 HIGH | Regular Expression Denial of Service (ReDoS) |
| CVE-2021-41573 | 7.5 HIGH | Hitachi Content Platform Anywhere (HCP-AW) 信息泄露漏洞 |
| CVE-2021-35945 | Couchbase Server 缓冲区错误漏洞 | |
| CVE-2021-22947 | Migration Toolkit For Containers 数据伪造问题漏洞 | |
| CVE-2021-22946 | libcurl 安全漏洞 | |
| CVE-2021-33923 | Confluent Ansible 安全漏洞 | |
| CVE-2021-33924 | Confluent Ansible 安全漏洞 | |
| CVE-2021-40651 | OS4Ed OpenSIS 路径遍历漏洞 | |
| CVE-2021-41732 | Zeek 环境问题漏洞 | |
| CVE-2021-41764 | Streama 跨站请求伪造漏洞 | |
| CVE-2021-41824 | Pixel&tonic Craft CMS 代码注入漏洞 | |
| CVE-2021-35943 | Couchbase Server 授权问题漏洞 | |
| CVE-2021-35944 | Couchbase Server 缓冲区错误漏洞 | |
| CVE-2021-3653 | KVM 权限许可和访问控制问题漏洞 | |
| CVE-2021-41795 | Apple Safari 安全漏洞 | |
| CVE-2020-20128 | LaraCms 信息泄露漏洞 | |
| CVE-2020-20129 | LaraCms 跨站脚本漏洞 | |
| CVE-2020-20131 | LaraCms 跨站脚本漏洞 | |
| CVE-2020-20781 | UCMS 跨站脚本漏洞 | |
| CVE-2021-41821 | Wazuh 数字错误漏洞 |
No comments yet