漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Migration-planner: unprotected delete endpoint wipes all tenant data
Vulnerability Description
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Migration Planner UI 访问控制错误漏洞
Vulnerability Description
Migration Planner UI是KubeV2V开源的一个迁移规划前端工具。 Migration Planner UI存在访问控制错误漏洞,该漏洞源于/api/v1/sources路由缺少适当的授权和过滤,可能导致经过身份验证的用户发送DELETE请求破坏所有客户数据,包括源、代理和评估,导致整个SaaS平台的可用性和完整性严重损失。
CVSS Information
N/A
Vulnerability Type
N/A