漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ShellHub: Crash-DoS via field injection in filter and sort-by parameters
Vulnerability Description
ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-encoded filter query parameter and the sort_by query parameter, which are then passed directly as BSON/SQL keys in the database layer without validation. Any authenticated user can craft payloads that cause the aggregation / query to fail and the API to return HTTP 500 with no body, with no rate limiting applied. This vulnerability is fixed in 0.24.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Vulnerability Type
输入验证不恰当
Vulnerability Title
ShellHub 输入验证错误漏洞
Vulnerability Description
ShellHub是ShellHub开源的一个远程设备访问与管理平台。 ShellHub 0.24.2之前版本存在输入验证错误漏洞,该漏洞源于设备列表端点接受用户控制的标识符作为BSON/SQL键且未验证,允许经过身份验证的用户构造有效载荷导致聚合查询失败。
CVSS Information
N/A
Vulnerability Type
N/A