Kurrier 是一个现代化的、自托管的工作空间,支持电子邮件、日历、联系人和存储功能。在版本 1.2.4 之前,Kurrier 的 API 端点在列出和检索 webhook 及身份(identity)资源时,未对经过身份验证的 API 请求实施资源所有权检查。拥有有效 API 密钥的攻击者可以利用其他账户的标识符,通过以下接口读取和枚举属于这些账户的 webhook 及身份资源: 匿名请求和无效的 API 密钥会被拒绝,跨用户的修改操作也被阻止,但受影响的 GET 和列表操作仍可能泄露其他用户的资源元数据。该问题
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kurrier-org | kurrier | < 1.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kurrier-org | kurrier | < 1.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet