漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenViking < 0.3.3 Missing Authorization via Task Polling
Vulnerability Description
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
OpenViking 安全漏洞
Vulnerability Description
OpenViking是Volcengine开源的一个人工智能代理的上下文数据库。 OpenViking 0.3.3之前版本存在安全漏洞,该漏洞源于缺少授权,可能导致未经授权的攻击者枚举或检索其他用户创建的后台任务元数据。
CVSS Information
N/A
Vulnerability Type
N/A