TencentCloud Octop 版本 1.0.2b6 及之前版本存在一个缺失授权验证的安全漏洞。该漏洞允许已认证的、低权限用户通过访问 和 接口,读取已存储的提供商 API 密钥。攻击者可以通过查询这些仅验证 JWT(JSON Web Token)的端点,获取明文的大语言模型(LLM)和语音提供商 API 密钥,进而滥用上游提供商的账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TencentCloud | Octop | ≤ 1.0.2b6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TencentCloud | Octop | 0 ~ 1.0.2b6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet