漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
Vulnerability Description
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and stores a public share record without checking whether the target file currently exists. Later, when a file is created at that same path, the previously created public share immediately becomes valid and exposes the new file through `GET /api/public/dl/<hash>`. This vulnerability is fixed in 2.63.7.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
File Browser 授权问题漏洞
Vulnerability Description
FileBrowser是filebrowser团队开源的一个文件管理界面,在指定的目录,它可以用来上传、删除、预览和编辑文件。 filebrowser 2.63.7之前版本存在授权问题漏洞,该漏洞源于在对任意路径发起的POST /api/share/<path>请求中,接受经过身份验证的请求并存储公共共享记录,但未检查目标文件当前是否存在,可能导致稍后在同一路径创建文件时,先前创建的公共共享立即生效,并通过GET /api/public/dl/<hash>暴露新文件。
CVSS Information
N/A
Vulnerability Type
N/A