在 Metasploit 框架的 JSON-RPC Web 服务接口中,发现了一个逻辑漏洞(故障开放条件)。当数据库健康检查(db.check)过程中发生异常,且环境变量 MSF_WS_JSON_RPC_API_TOKEN 未被显式设置时,应用程序会将内部状态标志 msf.auth_initialized 重置为 false。ApiToken Warden 认证策略将该 false 值误解为“认证未初始化或无需认证”的指示,从而向 JSON-RPC 请求分发器授予了未经身份验证的本地访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Metasploit-framework | 0 ~ 6.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet