漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Klaw has an improper authorisation check on /resetMemoryCache
Vulnerability Description
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
授权机制不恰当
Vulnerability Title
Klaw 授权问题漏洞
Vulnerability Description
Klaw是Aiven Open开源的一个操作系统工具。 Klaw 2.10.2之前版本存在授权问题漏洞,该漏洞源于访问控制不当,可能导致未经授权的用户触发重置或删除任何租户的元数据。
CVSS Information
N/A
Vulnerability Type
N/A