在 In Progress® Telerik® Report Server 12.2.26.1007 版本之前,由于服务代理(service-agent)SignalR 中心存在错误权限分配漏洞,攻击者可以使用经过认证的用户(包括拥有有效承载令牌的低权限或访客账户)注册为受信任的服务代理。在下一次服务器设置同步事件发生时,恶意代理将接收到存储配置和加密私钥。该权限提升漏洞会导致受保护的秘密信息泄露,包括已存储的数据源凭据和连接字符串,同时允许攻击者冒充代理并干扰任务调度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Telerik Report Server | 0 ~ 12.2.26.1007 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet