Insomnia是Insomnia公司的一个开源、跨平台 API 客户端,适用于 GraphQL、REST、WebSockets、服务器发送事件和 gRPC。 Insomnia 2023.4.0版本存在安全漏洞,该漏洞源于使用 DYLD_INSERT_LIBRARIES 环境变量可以执行代码并访问受限文件,或请求 TCC 权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-22618 | 8.1 HIGH | Nokia WaveLite 安全漏洞 |
| CVE-2023-3361 | 7.7 HIGH | S3 credentials included when exporting elyra notebook |
| CVE-2023-1832 | 6.8 MEDIUM | Improper authorization check in the server component |
| CVE-2022-4132 | 5.9 MEDIUM | Memory leak on tls connections |
| CVE-2023-3153 | 5.3 MEDIUM | Service monitor mac flow is not rate limited |
| CVE-2023-43261 | Milesight 日志信息泄露漏洞 | |
| CVE-2023-43838 | Personal Management System 代码问题漏洞 | |
| CVE-2023-27121 | Pleasant Solutions Pleasant Password Server 跨站脚本漏洞 | |
| CVE-2023-36619 | Atos Unify OpenScape 输入验证错误漏洞 | |
| CVE-2023-36618 | Atos Unify OpenScape 操作系统命令注入漏洞 | |
| CVE-2023-44075 | PHPGurukul Small CRM 跨站脚本漏洞 | |
| CVE-2023-43877 | RiteCMS 跨站脚本漏洞 | |
| CVE-2023-43321 | Digital China Networks DCFW-1800-SDC 代码问题漏洞 | |
| CVE-2023-35803 | Extreme Networks IQ Engine 安全漏洞 |
No comments yet