Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NTLMv2 hash disclosure via UNC path handling on Windows
Vulnerability Description
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
vitejs launch-editor 信任管理问题漏洞
Vulnerability Description
vitejs launch-editor是vitejs的开发者工具。 vitejs launch-editor 2.14.1之前版本存在安全漏洞,该漏洞源于访问任意路径包括Windows UNC路径,可能导致用户NTLMv2密码哈希被泄露至攻击者控制的SMB服务器,进而通过离线密码破解导致凭证泄露。
CVSS Information
N/A
Vulnerability Type
N/A