漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Better Auth before 1.4.5 Path Normalization Bypass via rou3
Vulnerability Description
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. The issue does not apply in deployments where the proxy or platform normalizes URLs by collapsing multiple slashes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
better-auth 输入验证错误漏洞
Vulnerability Description
better-auth是better-auth团队开源的一个身份验证框架。 better-auth 1.4.5之前版本存在输入验证错误漏洞,该漏洞源于路径规范化处理不当,可能导致攻击者通过提交带有额外斜杠的URL路径绕过禁用路径配置和基于路径的速率限制。
CVSS Information
N/A
Vulnerability Type
N/A