漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kong Insomnia profapi.dll untrusted search path
Vulnerability Description
A vulnerability was found in Kong Insomnia up to 10.3.0 and classified as critical. This issue affects some unknown processing in the library profapi.dll. The manipulation leads to untrusted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The real existence of this vulnerability is still doubted at the moment. The vendor is not able to reproduce the issue.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
Insomnia 代码问题漏洞
Vulnerability Description
Insomnia是Insomnia公司的一个开源、跨平台 API 客户端,适用于 GraphQL、REST、WebSockets、服务器发送事件和 gRPC。 Insomnia 10.3.0版本之前存在代码问题漏洞,该漏洞源于profapi.dll包含一个不受信任的搜索路径问题。
CVSS Information
N/A
Vulnerability Type
N/A