Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Retool 安全漏洞
Vulnerability Description
Retool是Retool公司的一个平台。可以使用代码、设计、调试、审查和部署功能开发任何内容。 Retool 3.40.0版本及之前版本存在安全漏洞,该漏洞源于资源认证凭证被插入到发送的数据中。
CVSS Information
N/A
Vulnerability Type
N/A