漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
API key leak in codeium-chrome
Vulnerability Description
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker to host a website that will steal the user's Codeium api-key, and thus impersonate the user on the backend autocomplete server. This issue has not been addressed. Users are advised to monitor the usage of their API key.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
codeium-chrome 安全漏洞
Vulnerability Description
codeium-chrome是Chrome Web浏览器的开源代码完成插件。 Chrome plugin codeium-chrome v1.2.52版本存在安全漏洞,该漏洞源于Service Worker 在接收外部消息时不会检查发送者,允许攻击者托管一个网站,窃取用户的 Codeium api 密钥。
CVSS Information
N/A
Vulnerability Type
N/A