漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenViking Missing root_api_key Allows Anonymous ROOT Access
Vulnerability Description
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers to access administrative functions including account management, resource operations, and system configuration.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
OpenViking 访问控制错误漏洞
Vulnerability Description
OpenViking是Volcengine开源的一个人工智能代理的上下文数据库。 OpenViking 0.1.18及之前版本存在访问控制错误漏洞,该漏洞源于访问控制破坏,可能导致未经授权的攻击者在root_api_key配置省略时获得ROOT权限。
CVSS Information
N/A
Vulnerability Type
N/A