data.all是data-dot-all开源的一个开源开发框架。 data.all 2.6.0之前版本存在安全漏洞,该漏洞源于经过身份验证的用户能够对data.all中持久保存的通知记录执行变异UPDATE操作,以针对其用户不是其成员的组通知。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-52311 | 6.3 MEDIUM | data.all does not invalidate authentication token upon user logout |
| CVE-2024-52312 | 5.4 MEDIUM | data.all authenticated users can perform restricted operations against DataSets and Enviro |
| CVE-2024-52314 | 4.9 MEDIUM | data.all admin user may access potentially sensitive data stored by producers via logs |
| CVE-2024-52313 | 4.3 MEDIUM | data.all authenticated users can obtain incorrect object level authorizations |
No comments yet