Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system directories. Attackers can bypass these restrictions by accessing subdirectories of blacklisted paths.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zenoss 安全漏洞
Vulnerability Description
Zenoss是美国Zenoss公司的一套开源的企业级IT管理和监控软件。该软件提供事件管理、网络服务监控、主机资源监控和网络设备的可用性监控等功能。 Zenoss 9.8.2之前版本存在安全漏洞,该漏洞源于is_dangerous_path验证函数逻辑缺陷,可能导致经过身份验证的攻击者读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A