漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge
Vulnerability Description
The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hijack the WhatsApp session. This allows the attacker to send messages on behalf of the user, intercept all incoming messages and media in real-time, and capture authentication QR codes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
nanobot 安全漏洞
Vulnerability Description
nanobot是✨Data Intelligence Lab@HKU✨开源的一个轻量个人AI助手。 Nanobot存在安全漏洞,该漏洞源于WhatsApp bridge组件默认将WebSocket服务器绑定到所有网络接口且无需身份验证,可能导致会话劫持和信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A