脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Authentication bypass in Alpine
脆弱性説明
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains condition will hold and will return from the authentication filter without aborting the request. Note that the principal object will not be assigned and therefore the issue wont allow user impersonation. This issue has been fixed in version 1.10.4. There are no known workarounds.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
脆弱性タイプ
认证机制不恰当
脆弱性タイトル
Alpine 授权问题漏洞
脆弱性説明
Alpine是一款电子邮件程序。 Alpine 1.10.4之前版本存在授权问题漏洞,该漏洞源于允许绕过身份验证过滤器。
CVSS情報
N/A
脆弱性タイプ
N/A