在 Kener 4.0.0 至 4.1.6(不含 4.1.6)版本中存在一个信息泄露漏洞。该漏洞允许未认证的攻击者通过查询缺少可见性过滤器的 Dashboard API 处理程序,获取隐藏或已停用的监控数据。攻击者可以使用已知或猜測的监控标签,向诸如 monitor-bar 和 monitor-latency-chart 等端点发起请求,从而获取监控项的名称、描述、状态、运行历史记录以及延迟信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rajnandan1 | kener | 4.0.0 ~ 4.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet