Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Outline has a suspended user authentication bypass via WebSocket connections
Vulnerability Description
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
Outline 授权问题漏洞
Vulnerability Description
Outline是Outline开源的一个知识库。 Outline 1.1.0之前版本存在授权问题漏洞,该漏洞源于WebSocket身份验证机制存在缺陷,可能导致被暂停用户维持或建立实时WebSocket连接并继续接收敏感操作更新。
CVSS Information
N/A
Vulnerability Type
N/A