Soft Machine 是一个基于虚拟机的智能体开发环境/云操作系统。在 0.2.247 及更早版本中, 中的两个身份验证辅助函数 和 接受全局的 作为 Bearer Token,但未验证调用者所属的工作区。由于该密钥在 Fly 应用中的每个容器上都设置为相同的值,并且可以从每个工作区内的用户可见进程环境中访问,因此任何租户都可以使用该密钥向其他租户的工作区 API 进行身份验证。其结果是,任何付费客户的 shell 都可以访问跨工作区的读取、写入以及破坏性恢复操作。现有的每工作区令牌检查机制( )保护了面向用户
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Soft-Machine-io | security | <= 0.2.247 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet