漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Migration-planner: getsourcedownloadurl missing organization check
Vulnerability Description
A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. Consequently, the attacker can download OVA images containing sensitive information, such as long-lived agent JSON Web Tokens (JWTs) and source configurations, potentially leading to unauthorized access and modification of the victim's source.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Migration assessment 安全漏洞
Vulnerability Description
Migration assessment是KubeV2V开源的一个VMware环境评估与迁移建议工具。 Migration assessment存在安全漏洞,该漏洞源于/api/v1/sources/{id}/image-url端点存在访问控制不当,可能导致经过身份验证的攻击者绕过所有权检查获取其他用户的OVA镜像的预签名S3 URL,从而下载包含敏感信息的OVA镜像,可能导致未经授权的访问和修改受害者源。
CVSS Information
N/A
Vulnerability Type
N/A