漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion
Vulnerability Description
FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in a way that persists a server-owned datasetId value from another tenant. This creates mixed dataset objects and downstream dataset, collection, and training endpoints then make authorization decisions from inconsistent ownership anchors, allowing cross-tenant read, update, and delete access when mixed object ids are known. This issue is fixed in version 4.15.0-beta4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-915
Vulnerability Title
labring FastGPT 输入验证错误漏洞
Vulnerability Description
labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.14.17版本至4.15.0-beta4之前版本存在输入验证错误漏洞,该漏洞源于授权决策不一致,允许认证的租户用户调用POST /api/core/dataset/collection/create/reTrainingCollection时持久化另一个租户的服务器拥有的datasetId值,从而导致跨租户读取、更新和删除访问。
CVSS Information
N/A
Vulnerability Type
N/A