漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer
Vulnerability Description
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Vulnerability Title
FTL 竞争条件问题漏洞
Vulnerability Description
FTL是Pi-hole开源的一个网络广告拦截与统计工具。 FTL 6.6.1之前版本存在竞争条件问题漏洞,该漏洞源于HTTP会话管理子系统中的竞争条件问题,可能导致攻击者利用该漏洞进行未授权操作。
CVSS Information
N/A
Vulnerability Type
N/A