漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
mosaxiv clawlet File Tools fs_ops.go edit_file link following
Vulnerability Description
A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of the component File Tools. Performing a manipulation results in link following. The attack needs to be approached locally. The reported GitHub issue was closed with the label "not planned".
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
mosaxiv clawlet 后置链接漏洞
Vulnerability Description
mosaxiv clawlet是mosaxiv个人开发者的一款服务器管理软件。 mosaxiv clawlet 0.2.0版本、0.2.1版本、0.2.2版本、0.2.3版本、0.2.4版本、0.2.5版本、0.2.6版本、0.2.7版本、0.2.8版本、0.2.9版本和0.2.10版本存在后置链接漏洞,该漏洞源于File Tools组件tools/fs_ops.go文件中的read_file/write_file/edit_file函数存在问题,导致链接跟随,攻击者需本地发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A