Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
DeepAudit Affected by User Enumeration via Broken Access Control
Vulnerability Description
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated user to enumerate all users in the system and retrieve sensitive information including email addresses, phone numbers, full names, and role information.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
DeepAudit 安全漏洞
Vulnerability Description
DeepAudit是lintsinghua个人开发者的一个自动化漏洞审计工具。 DeepAudit 3.0.4及之前版本存在安全漏洞,该漏洞源于/api/v1/users/端点存在访问控制不当,可能允许任何经过身份验证的用户枚举系统中的所有用户并检索敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A