Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Aurora: padding oracle can allow construction an authentication cookie
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a valid authentication cookie. Potentially this could be combined with vulnerabilities in other components to achieve remote code execution. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Apache Aurora 信息泄露漏洞
Vulnerability Description
Apache Aurora是美国阿帕奇(Apache)基金会的一个用于长时间运行的服务和 cron 作业的 Mesos 框架。 Apache Aurora 0.5.0及之后版本存在信息泄露漏洞,该漏洞源于允许未经授权的攻击者获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A