Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Better Auth before 1.4.5 Path Normalization Bypass via rou3
Vulnerability Description
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. The issue does not apply in deployments where the proxy or platform normalizes URLs by collapsing multiple slashes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
better-auth 输入验证错误漏洞
Vulnerability Description
better-auth是better-auth团队开源的一个身份验证框架。 better-auth 1.4.5之前版本存在输入验证错误漏洞,该漏洞源于路径规范化处理不当,可能导致攻击者通过提交带有额外斜杠的URL路径绕过禁用路径配置和基于路径的速率限制。
CVSS Information
N/A
Vulnerability Type
N/A