OpenCTI是OpenCTI组织开源的一个开放网络威胁情报平台。 OpenCTI 7.260326.0之前版本存在授权问题漏洞,该漏洞源于授权绕过问题,允许具有KNOWLEDGE_KNUPDATE权限的任何已验证用户通过注入synchronized-upsert: true HTTP标头,绕过置信度级别验证和对象标记限制,从而降低置信度级别、移除安全标记(如TLP:RED)、操纵关系,并影响STIX对象类型,包括Indicator、ThreatActor、Malware和Report。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenCTI-Platform | opencti | < 7.260326.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenCTI-Platform | opencti | < 7.260326.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet