Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-45050
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ringer Server Does Not Check Members When Loading Messages
Source: NVD (National Vulnerability Database)
Vulnerability Description
Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user loading the conversation is actually a member of that conversation. This allows any user with a Lif Account to load any conversation between two users without permission. This issue had been patched in version 1.3.1. There is no action required for users. Lif Platforms will update their servers with the patch.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
New-Ringer-Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
New-Ringer-Server是Lif Platforms开源的一个 Ringer 消息应用程序的服务器代码。 New-Ringer-Server 1.3.1之前版本存在安全漏洞,该漏洞源于加载消息路由时未检查加载会话的用户是否确实是该会话的成员,这允许任何拥有Lif帐户的用户未经授权加载任意用户的会话。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Lif-PlatformsNew-Ringer-Server < 1.3.1 -
II. Public POCs for CVE-2024-45050
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-45050
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-45050

No comments yet


Leave a comment