漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Velociraptor directory traversal via the NewNotebook API
Vulnerability Description
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rapid7 velociraptor 路径遍历漏洞
Vulnerability Description
Rapid7 velociraptor是美国Rapid7公司开源的一款终端安全与响应工具。 Rapid7 velociraptor 0.77.2之前版本存在路径遍历漏洞,该漏洞源于对NewNotebook API参数清理不足,可能允许具有NOTEBOOK_EDIT权限的认证用户将笔记记录写入组织数据存储目录之外,覆盖其他元数据文件,导致数据损坏。
CVSS Information
N/A
Vulnerability Type
N/A