在 notionnext-org 的 NotionNext 项目(版本最高至 4.10.10)中发现了一个安全漏洞。受此问题影响的是“身份验证守卫”(Authentication Guard)组件中 文件内的 函数。由于对参数 的处理不当,导致缺少必要的身份验证机制。该漏洞可被远程利用。 在版本 4.1.0 至 4.9.5.2 中,由于缺少方法检查,允许未授权的攻击者直接利用该漏洞。 在版本 4.9.5.7 至 4.10.10 中,虽然存在身份验证守卫,但其仅在环境变量 被设置时才会生效。默认部署情况下,系统仍处于
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notionnext-org | NotionNext | 4.10.0 |
cpe:2.3:a:notionnext-org:notionnext:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet