Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affected function is preHandle In the filter code, use CodecUtils.urlDecode(request.getRequestURI()) to obtain the URL-decoded request path, and then determine whether the path endsWith /error. If so, execute return true to skip this Interceptor. Else, redirect to /user/login api. Allowing unauthenticated attackers to gain sensitive information or escalated privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Rebuild 安全漏洞
Vulnerability Description
Rebuild是getrebuild开源的一个高度可定制化的企业管理系统。 Rebuild 4.0.4版本存在安全漏洞,该漏洞源于RebuildWebInterceptor类过滤代码存在缺陷,可能导致信息泄露或权限提升。
CVSS Information
N/A
Vulnerability Type
N/A