漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FlagForgeCTF Exposes User Emails via Public /api/user/[username] API
Vulnerability Description
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.2 or later to eliminate exposure. There are no workarounds for this vulnerability.
CVSS Information
N/A
Vulnerability Type
侵犯隐私
Vulnerability Title
Flag Forge 安全漏洞
Vulnerability Description
Flag Forge是FlagForge开源的一个易于使用的CTF平台。 Flag Forge 2.0.0版本至2.3.1之前版本存在安全漏洞,该漏洞源于公开端点/api/user/[username]返回用户电子邮件地址,可能导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A