漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName
Vulnerability Description
TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ publicly served result paths, enabling arbitrary content hosting and potential stored XSS on the storage origin. ../ traversal is blocked by S3/MinIO canonicalization (signature mismatch), but forward-slash path injection is exploitable. This issue has been fixed in version 3.17.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
baptisteArno typebot.io 路径遍历漏洞
Vulnerability Description
baptisteArno typebot.io是baptisteArno的开源在线表单构建工具。 baptisteArno typebot.io 3.17.0之前版本存在安全漏洞,该漏洞源于未清理的fileName输入在构建public/ S3对象键时存在问题,可能导致匿名访问者上传攻击者控制的HTML、SVG或JS文件,实现任意内容托管和潜在的存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A