脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
脆弱性説明
JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
脆弱性タイプ
大小写敏感处理不恰当
脆弱性タイトル
jupyterlab-git 输入验证错误漏洞
脆弱性説明
JupyterLab jupyterlab-git是JupyterLab基金会开源的一个 JupyterLab 的 Git 扩展。 jupyterlab-git 0.54.0之前版本存在输入验证错误漏洞,该漏洞源于在jupyterlab_git/handlers.py中使用fnmatch.fnmatchcase()来强制执行排除路径,可能导致经过身份验证的用户通过不区分大小写的文件系统更改URL路径大小写并读取排除目录。
CVSS情報
N/A
脆弱性タイプ
N/A