Immich 3.3.1 及之前版本中存在一个授权缺失漏洞,位于配对同步流(partner synchronization stream)中。该漏洞允许已认证的配对用户访问“锁定文件夹”中资产的元数据,因为同步查询未排除锁定可见性。拥有活跃配对关系的攻击者可以调用 接口,并指定 和 类型,从而获取 GPS 坐标、拍摄时间、描述信息以及相机详细数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| immich-app | immich | ≤ 3.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| immich-app | immich | 0 ~ 3.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet