漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WeKan < 8.19 Read-only Board Roles Can Update Cards
Vulnerability Description
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
WeKan 安全漏洞
Vulnerability Description
WeKan是WeKan开源的一个看板应用程序。 WeKan 8.19之前版本存在安全漏洞,该漏洞源于某些卡片更新API路径仅验证看板读取权限而非要求写入权限,可能导致具有只读角色的用户执行需要写入权限的卡片更新。
CVSS Information
N/A
Vulnerability Type
N/A