漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Checkmate: Pre-auth Denial of Service via File Upload on Registration
Vulnerability Description
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through in-memory Multer parsing before registration validation, without file-size, file-count, or MIME-type limits in server/src/api/middleware/upload.ts. An unauthenticated attacker can submit concurrent oversized files that are buffered before invalid registration or invite-token checks reject the request, exhausting memory and crashing or destabilizing the backend. This issue is fixed in version 3.9.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
BlueWave Labs Checkmate 资源管理错误漏洞
Vulnerability Description
BlueWave Labs Checkmate是BlueWave Labs组织的一款监控与运维管理工具。 BlueWave Labs Checkmate 3.9.1之前版本存在资源管理错误漏洞,该漏洞源于/api/v1/auth/register路由对multipart profileImage上传缺少文件大小、文件数量及MIME类型限制,可能导致未经验证的攻击者提交并发超大文件,耗尽内存并导致后端崩溃或失稳。
CVSS Information
N/A
Vulnerability Type
N/A