Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity Spoofing
Vulnerability Description
PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
PubNet 安全漏洞
Vulnerability Description
PubNet是Ricardo Boss个人开发者的一个自托管软件包仓库。 PubNet 1.1.3之前版本存在安全漏洞,该漏洞源于/api/storage/upload端点未经验证,可能导致身份欺骗和权限提升。
CVSS Information
N/A
Vulnerability Type
N/A