Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Insomnia 安全漏洞
Vulnerability Description
Insomnia是Insomnia公司的一个开源、跨平台 API 客户端,适用于 GraphQL、REST、WebSockets、服务器发送事件和 gRPC。 Insomnia 2023.4.0版本存在安全漏洞,该漏洞源于使用 DYLD_INSERT_LIBRARIES 环境变量可以执行代码并访问受限文件,或请求 TCC 权限。
CVSS Information
N/A
Vulnerability Type
N/A