漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
CVSS Information
N/A
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Chainlit 安全漏洞
Vulnerability Description
Chainlit是chainlit开源的一个大模型对话界面框架。 Chainlit 2.8.5之前版本存在安全漏洞,该漏洞源于存在通过用户控制密钥的授权绕过,可能导致攻击者登录后查看线程或获取线程所有权。
CVSS Information
N/A
Vulnerability Type
N/A