Flame 2.4.0 及更早版本中存在一个信息泄露漏洞,位于未认证的 接口。该接口在未对字段进行脱敏的情况下直接返回完整的配置对象。攻击者只需发送一次未认证的请求,即可获取存储的天气 API 密钥及内部运营设置,从而消耗提供商配额或访问敏感配置数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pawelmalak | flame | 0 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100501 | 6.5 MEDIUM | Flame through 2.4.0 Brute-Force Attack via Login Endpoint |
| CVE-2026-100502 | 5.0 MEDIUM | Flame through 2.4.0 Admin Token Insufficient Session Expiration |
No comments yet