漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
Vulnerability Description
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:create` or `client:update` permissions to escalate their privileges to owner-level. Version 2.69.1 fixes the issue. No known workarounds are available.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Fides 安全漏洞
Vulnerability Description
Fides是Ethyca开源的一个开源隐私工程平台,用于管理运行时环境中数据隐私请求的实现以及代码中隐私法规的执行。 Fides 2.69.1之前版本存在安全漏洞,该漏洞源于OAuth客户端创建和更新端点存在权限提升。
CVSS Information
N/A
Vulnerability Type
N/A