漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Helix Front (UI): Helix front hard-coded secret in the express-session
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Information
N/A
Vulnerability Type
将资源暴露给错误范围
Vulnerability Title
Apache Helix 安全漏洞
Vulnerability Description
Apache Helix是美国阿帕奇(Apache)基金会的一个通用集群管理框架。用于自动管理托管在节点集群上的分区、复制和分布式资源。 Apache Helix存在安全漏洞,该漏洞源于包含硬编码的机密,允许攻击者通过生成自己的虚假cookie来欺骗会话。
CVSS Information
N/A
Vulnerability Type
N/A