漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
Vulnerability Description
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
认证机制不恰当
Vulnerability Title
penpot 授权问题漏洞
Vulnerability Description
penpot penpot是penpot公司开源的一款开源的设计和原型制作平台。 penpot 2.14.5之前版本存在授权问题漏洞,该漏洞源于暴露邀请令牌和未进行密码验证,可能导致注册用户接管任何非封锁配置文件。
CVSS Information
N/A
Vulnerability Type
N/A