漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Dokploy: Invitation Role Escalation Allows Organization Takeover
Vulnerability Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Dokploy 权限许可和访问控制问题漏洞
Vulnerability Description
Dokploy是Dokploy团队开源的一款集持续集成与交付于一体的云计算部署平台。 Dokploy 0.29.6之前版本存在权限许可和访问控制问题漏洞,该漏洞源于apps/dokploy/server/api/routers/organization.ts中organization.inviteMember tRPC过程允许具有member:create权限的用户邀请拥有owner角色的账户,且packages/server/src/services/user.ts允许特权自托管用户创建任意角色账户,导
CVSS Information
N/A
Vulnerability Type
N/A