漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Vulnerability Description
The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Google Cloud Storage for Craft CMS 信息泄露漏洞
Vulnerability Description
Google Cloud Storage for Craft CMS是Craft CMS开源的一个云存储集成插件。 Google Cloud Storage for Craft CMS 2.2.1之前版本存在信息泄露漏洞,该漏洞源于DefaultController->actionLoadBucketData端点访问控制不当,可能导致未经验证的用户查看存储桶列表。
CVSS Information
N/A
Vulnerability Type
N/A