Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
Vulnerability Description
Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
在信任Cookie未进行验证与完整性检查
Vulnerability Title
Nathan Esquenazi Hermes WebUI 会话机制问题漏洞
Vulnerability Description
nesquena Hermes WebUI是nesquena的Web服务器。 Nathan Esquenazi Hermes WebUI 0.51.368之前版本存在会话机制问题漏洞,该漏洞源于get_profile_cookie()函数接受未经验证的profile名称,可能导致经过身份验证的攻击者伪造hermes_profile cookie值绕过基于profile的授权检查,跨不同profile访问会话、文件和资源。
CVSS Information
N/A
Vulnerability Type
N/A