Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server
Vulnerability Description
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
UncleCode Crawl4AI 授权问题漏洞
Vulnerability Description
UncleCode Crawl4AI是新加坡UncleCode个人开发者的一款AI驱动的爬虫软件。 UncleCode Crawl4AI 0.8.7之前版本存在授权问题漏洞,该漏洞源于监控路由端点存在身份验证绕过,可能导致未经身份验证的攻击者调用/monitor/actions/cleanup端点并操作监控状态,造成服务中断。
CVSS Information
N/A
Vulnerability Type
N/A