漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenBao has Reflected XSS in its OIDC authentication error message
Vulnerability Description
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a failed authentication. This allows an attacker access to the token used in the Web UI by a victim. The `error_description` parameter has been replaced with a static error message in v2.5.2. The vulnerability can be mitigated by removing any roles with `callback_mode` set to `direct`.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
OpenBao 安全漏洞
Vulnerability Description
OpenBao是OpenBao开源的一个敏感数据管理软件。 OpenBao 2.5.2之前版本存在安全漏洞,该漏洞源于身份验证失败页面上的error_description参数存在跨站脚本,可能导致攻击者访问受害者在Web UI中使用的令牌。
CVSS Information
N/A
Vulnerability Type
N/A