漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Microsoft UFO accepts cross-device TASK_END messages by session_id only, allowing peer task-result injection
Vulnerability Description
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message came from the device that originally received the task. When the constellation sends a task to a target device, it records a pending Future under a session key. The pending task record stores the expected device ID, but the completion path ignores that binding. If another authenticated peer device sends a forged TASK_END with the same session_id, the constellation accepts the response and completes the victim device's pending Future with attacker-controlled result data. This is an authenticated cross-device task-result injection issue.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
Vulnerability Type
使用捕获-重放进行的认证绕过
Vulnerability Title
UFO³ 数据伪造问题漏洞
Vulnerability Description
UFO³是Microsoft开源的一个跨设备协作的多智能体任务编排工具。 UFO³ 3.0.1-4-ge2626659版本存在数据伪造问题漏洞,该漏洞源于任务响应仅通过session_id追踪而未验证来源设备,可能导致跨设备任务结果注入。
CVSS Information
N/A
Vulnerability Type
N/A