bbs-go 4.4.6 及更早版本中存在一个权限绕过漏洞,位于 AdminMiddleware 的授权逻辑中。该漏洞的原因是:只读的 权限规则在匹配 端点时,优先于预期的 规则生效。因此,仅拥有查看权限的已认证用户可以调用 端点,触发高开销的全表用户计数和缓存失效操作。通过反复并发执行这些数据库操作,攻击者可导致拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet