Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2026-18744
Vulnerability Description
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected + statement text cross-tenant.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CERT/CC VINCE 授权问题漏洞
Vulnerability Description
CERT Coordination Center VINCE是CERT Coordination Center组织的一个支持漏洞披露与协调的平台。 CERT/CC VINCE 3.0.44之前版本存在授权问题漏洞,该漏洞源于test_func仅检查_is_my_case而未检查kwargs['member']的所有权,导致任何已认证的案件参与者可通过提供其他成员ID获取其他厂商的CaseStatement和CaseMemberStatus,绕过share_status,泄露跨租户的受保护厂商受影响状态和声
CVSS Information
N/A
Vulnerability Type
N/A