Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Onyx 安全漏洞
Vulnerability Description
Onyx是Onyx开源的一个AI大模型平台。 Onyx 0.27.0版本存在安全漏洞,该漏洞源于update_user_group存在授权绕过漏洞,可能导致修改任意用户组。
CVSS Information
N/A
Vulnerability Type
N/A