漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Leantime - Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass
Vulnerability Description
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Leantime 授权问题漏洞
Vulnerability Description
Leantime是Leantime公司开源的一款项目管理软件。 Leantime 3.6.2及之前版本存在授权问题漏洞,该漏洞源于JSON-RPC方法缺少所有权检查、会话固定或权限属性门控,可能导致已认证用户读取任意用户的TOTP密钥或禁用双因素认证。
CVSS Information
N/A
Vulnerability Type
N/A