漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Capgo - Broken Object Level Authorization in Build Job Control via jobId Parameter
Vulnerability Description
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The handlers authorize the request based only on the attacker-controlled app_id supplied in the request body and never verify that the jobId in the URL belongs to that app_id (or the same tenant/org) before issuing privileged builder commands with the server-held builder API key. An authenticated user with the app.build_native permission for any app they control can start or cancel arbitrary builder jobs belonging to other tenants by supplying a victim jobId, resulting in cross-tenant build sabotage (denial of service), unauthorized compute actions, and potential billing impact.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
授权机制不恰当
Vulnerability Title
Capgo 授权问题漏洞
Vulnerability Description
Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于在/build/start/:jobId和/build/cancel/:jobId端点中存在对象级授权失效(BOLA)问题,处理程序仅基于请求体中攻击者控制的app_id进行授权验证,而从未验证URL中的jobId是否属于该app_id或同一租户/组织,便使用服务器持有的构建器API密钥下发特权构建命令,可能导致经过身份验证的用户跨租户构建破坏及拒
CVSS Information
N/A
Vulnerability Type
N/A