漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Coturn: Arbitrary File Write via CLI psd Command
Vulnerability Description
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process because the command string is used as-is after stripping the psd prefix and leading spaces, allowing truncation and overwrite with session dump data. This issue is fixed in version 4.13.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
Coturn 输入验证错误漏洞
Vulnerability Description
Coturn是Coturn组织开源的一款TURN(VoIP媒体业务NAT穿越服务器和网关)和STUN(用户数据报协议简单穿越网络地址转换器)Server的开源实现。 Coturn 4.13.0之前版本存在输入验证错误漏洞,该漏洞源于psd print sessions dump CLI命令对路径未进行验证,可能导致经过身份验证的管理员通过CLI访问覆盖可写文件。
CVSS Information
N/A
Vulnerability Type
N/A