漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the default admin account was found to be locked out via the web interface but still usable through the REST API. This allowed creation of a new privileged user, bypassing MFA protections. This undermines the intended security posture of MFA enforcement.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Obsidian Scheduler 安全漏洞
Vulnerability Description
Obsidian Scheduler是美国Obsidian公司的一个企业级任务调度器。 Obsidian Scheduler 5.0.0版本至6.3.0版本存在安全漏洞,该漏洞源于账户锁定后仍允许通过Basic Authentication进行身份验证,可能导致绕过MFA保护并创建特权用户。
CVSS Information
N/A
Vulnerability Type
N/A