Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Dokploy: Invitation Role Escalation Allows Organization Takeover
Vulnerability Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Dokploy 权限许可和访问控制问题漏洞
Vulnerability Description
Dokploy是Dokploy团队开源的一款集持续集成与交付于一体的云计算部署平台。 Dokploy 0.29.6之前版本存在权限许可和访问控制问题漏洞,该漏洞源于apps/dokploy/server/api/routers/organization.ts中organization.inviteMember tRPC过程允许具有member:create权限的用户邀请拥有owner角色的账户,且packages/server/src/services/user.ts允许特权自托管用户创建任意角色账户,导
CVSS Information
N/A
Vulnerability Type
N/A