Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OneUptime: Password Reset Token Logged at INFO Level
Vulnerability Description
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user. This vulnerability is fixed in 10.0.24.
CVSS Information
N/A
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
OneUptime 日志信息泄露漏洞
Vulnerability Description
OneUptime是OneUptime开源的一个全面的解决方案。用于监控和管理您的在线服务。 OneUptime 10.0.24之前版本存在日志信息泄露漏洞,该漏洞源于密码重置流程会记录包含明文重置令牌的完整URL,可能导致访问日志的攻击者拦截令牌并接管账户。
CVSS Information
N/A
Vulnerability Type
N/A