在 Fleet 4.89.0 之前的版本中,活动列表端点(GET /api/v1/fleet/activities 和 GET /api/v1/fleet/hosts/{id}/activities)存在 SQL 注入漏洞。已弃用的 cursor-pagination 辅助函数 appendListOptionsWithCursorToSQL 未使用允许列表(allowlist)校验,便将调用者提供的排序/排序方向键直接拼接到 SQL 的 ORDER BY 子句中,导致拥有活动读取权限的经认证用户能够按任意列对结果
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101045 | 8.0 HIGH | Fleet Homebrew Cask OS Command Injection via Metadata |
| CVE-2026-101047 | 5.3 MEDIUM | Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs |
No comments yet