Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Valinor error messages leading to potential data exfiltration
Vulnerability Description
Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should not have permission to do so. This is a problem with cases such as an SQL exception showing an SQL snippet, a database connection exception showing database IP address/username/password, or a timeout detail / out of memory detail. Attackers could use this information for potential data exfiltration, denial of service attacks, enumeration attacks, etc. Version 0.12.0 contains a patch for this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过错误消息导致的信息暴露
Vulnerability Title
Valinor 安全漏洞
Vulnerability Description
Valinor是帮助将任何输入映射到强类型值对象结构的 PHP 库。 Valinor 0.12.0 之前版本存在安全漏洞,该漏洞源于 Valinor 可以在没有权限的情况下使用 `Throwable#getMessage()`,例如显示 SQL 片段的 SQL 异常、显示数据库 IP 地址、用户名、密码、数据库连接异常、超时详细信息、内存不足等信息,攻击者可以利用该漏洞可以获取数据、拒绝服务攻击、枚举攻击等。
CVSS Information
N/A
Vulnerability Type
N/A