漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Winter vulnerable to Prototype Pollution in Snowboard framework
Vulnerability Description
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1321
Vulnerability Title
Winter 安全漏洞
Vulnerability Description
Winter是基于 Laravel PHP 框架的免费、开源、自托管 CMS 平台。 Winter 1.1.8、1.1.9 和 1.2.0 版本存在安全漏洞,该漏洞源于 Snowboard 框架容易受到 Snowboard 主类及其插件加载器中的原型污染。
CVSS Information
N/A
Vulnerability Type
N/A