漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Local file Inclusion via static file serving functionality in Mesop
Vulnerability Description
Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fixed in Mesop that could potentially allow unauthorized access to files on the server hosting the Mesop application. The vulnerability was related to insufficient input validation in a specific endpoint. This could have allowed an attacker to access files not intended to be served. Users are strongly advised to update to the latest version of Mesop immediately. The latest version includes a fix for this vulnerability. At time of publication 0.12.4 is the most recently available version of Mesop.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Google Mesop 安全漏洞
Vulnerability Description
Google Mesop是美国谷歌(Google)公司的一个基于 Python 的 UI 框架。 Google Mesop 0.9.0版本至0.12.4之前版本存在安全漏洞,该漏洞源于输入验证不足,可能允许未经授权访问服务器上的文件。
CVSS Information
N/A
Vulnerability Type
N/A