漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure
Vulnerability Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As of time of publication, no known patched versions are available. Until a patched release is applied, do not rely on passkey as the step-up method for privileged secure-verification actions; require TOTP/2FA for those actions where operationally possible; or temporarily restrict access to affected secure-verification-protected endpoints.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
New API 授权问题漏洞
Vulnerability Description
New API是QuantumNous开源的一个接口软件。 New API 0.10.0及之后版本存在授权问题漏洞,该漏洞源于通用安全验证流程存在逻辑缺陷,可能导致已注册通行密钥的认证用户无需完成WebAuthn断言即可通过安全验证。
CVSS Information
N/A
Vulnerability Type
N/A