漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Exposed tokens in SUSE Rancher AI Agent logs
Vulnerability Description
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Vulnerability Type
通过Debug信息导致的信息暴露
Vulnerability Title
Rancher AI Assistant for Rancher 调试信息泄露漏洞
Vulnerability Description
Rancher AI Assistant for Rancher是Rancher公司的一个用于用户交互的 UI 扩展。 Rancher AI Assistant for Rancher 1.0.2之前版本存在调试信息泄露漏洞,该漏洞源于设置DEBUG日志级别时可能导致信息泄露,将API密钥或包含敏感数据的LLM响应文本写入日志文件,允许本地攻击者滥用获取的数据或凭据。
CVSS Information
N/A
Vulnerability Type
N/A