Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DTStack Taier 安全漏洞
Vulnerability Description
Taier是袋鼠云(DTStack)开源的一个分布式调度系统。旨在降低 ETL 的成本,明确任务之间的复杂依赖关系,并降低提交、调度和运维方面的劳动力成本。 DTStack Taier 1.3.0版本存在安全漏洞,该漏洞源于Taier/API/tenant/listTenant 接口存在不安全权限,攻击者利用该漏洞可以通过 getCookie 方法查看敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A