漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Aurora: padding oracle can allow construction an authentication cookie
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora.
An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a valid authentication cookie. Potentially this could be combined with vulnerabilities in other components to achieve remote code execution.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Apache Aurora 信息泄露漏洞
Vulnerability Description
Apache Aurora是美国阿帕奇(Apache)基金会的一个用于长时间运行的服务和 cron 作业的 Mesos 框架。 Apache Aurora 0.5.0及之后版本存在信息泄露漏洞,该漏洞源于允许未经授权的攻击者获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A