漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect
Vulnerability Description
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp and Ollama provider sessions. Attackers can position themselves on the network path to receive cleartext HTTP requests carrying imported session cookies when a provider-controlled redirect target issues a redirect to a cleartext HTTP endpoint within the same provider domain.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
敏感数据的明文传输
Vulnerability Title
CodexBar 安全漏洞
Vulnerability Description
CodexBar是Peter Steinberger个人开发者的一款AI编程服务用量监控工具。 CodexBar 0.32.0之前版本存在安全漏洞,该漏洞源于会话Cookie泄露,可能导致网络攻击者利用Amp和Ollama提供商会话的重定向处理不当,拦截导入的浏览器会话Cookie。
CVSS Information
N/A
Vulnerability Type
N/A