Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OPA SMB Force-Authentication
Vulnerability Description
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Vulnerability Type
使用捕获-重放进行的认证绕过
Vulnerability Title
Open Policy Agent 安全漏洞
Vulnerability Description
Open Policy Agent(OPA)是Open Policy Agent开源的一个开源的通用策略引擎,可在整个堆栈中实现统一的、上下文感知的策略实施。 Open Policy Agent v0.68.0之前版本存在安全漏洞,该漏洞源于输入验证不当,存在SMB强制身份验证漏洞。
CVSS Information
N/A
Vulnerability Type
N/A