Authorizer 是一个开源、可自托管的认证与授权服务器。在 2.2.1 版本之前, 端点接受任意 ,而未将其与 进行校验。当 或 时,服务器会将 、 和 作为查询参数附加到响应中,并向攻击者提供的 URL 发起 302 重定向。未认证的攻击者可以从公开的 端点获取所需的 。在 v2.0.1 版本中,其他处理程序( 、 、 、 、 、 )已应用了部分修复,但 端点未被包含在内。2.2.1 版本包含了更完整的修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| authorizerdev | authorizer | < 2.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| authorizerdev | authorizer | < 2.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet