CERT Coordination Center VINCE是CERT Coordination Center组织的一个支持漏洞披露与协调的平台。 CERT/CC VINCE 3.0.44之前版本存在授权问题漏洞,该漏洞源于test_func仅检查_is_my_case而未检查kwargs['member']的所有权,导致任何已认证的案件参与者可通过提供其他成员ID获取其他厂商的CaseStatement和CaseMemberStatus,绕过share_status,泄露跨租户的受保护厂商受影响状态和声
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18749 | CVE-2026-18749 | |
| CVE-2026-18750 | CVE-2026-18750 |
No comments yet