OpenLIT 2.1.0 存在一个授权绕过漏洞,允许经过身份验证的用户通过伪造 头部读取其他项目的遥测数据。攻击者如果知道受害项目的 ID 和数据库配置 ID,就可以通过查询 trace 读取 API 获取包含 LLM 提示和完成内容的追踪信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet