漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Authentication Bypass in prefecthq/prefect
Vulnerability Description
In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication checks. This allows an attacker to create resources with names ending in 'health' or 'ready' and access them without authentication. Affected endpoints include those for variables, flows, work pools, work queues, and deployments. This vulnerability can lead to unauthorized access to sensitive information, such as API keys and database credentials, stored in Prefect Variables.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
Prefect 安全漏洞
Vulnerability Description
Prefect是Prefect开源的一款工作流编排工具,使开发人员能够构建、观察数据管道并对数据管道做出反应。 Prefect 3.6.19版本存在安全漏洞,该漏洞源于对健康检查探针的URL路径豁免处理不当,可能导致攻击者创建以health或ready结尾的资源并绕过身份验证访问,泄露存储在Prefect Variables中的API密钥和数据库凭据等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A