漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
signalk-server: Arbitrary Prototype Read via `from` Field Bypass
Vulnerability Description
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from the global prototype object this violates data isolation and lets a user read more than they should. This issue has been patched in version 2.24.0.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Signal K Server 信息泄露漏洞
Vulnerability Description
Signal K Server是Signal K开源的一个船用中央服务器。 Signal K Server 2.24.0之前版本存在信息泄露漏洞,该漏洞源于from字段绕过原型边界过滤,可能导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A