Fides是一个开源隐私工程平台,用于管理运行时环境中数据隐私请求的实现以及代码中隐私法规的执行。 Fides 2.39.2rc0之前版本存在安全漏洞,该漏洞源于 Fides Privacy Center 允许未认证的攻击者通过 HTTP GET 请求访问环境变量 SERVER_SIDE_FIDES_API_URL 的值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Fides versions 2.19.0 to before 2.39.2rc0 contain an information disclosure caused by unauthenticated HTTP GET request to the Privacy Center, letting attackers access the SERVER_SIDE_FIDES_API_URL, which may reveal server configuration details, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31223.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet