漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication Codes
Vulnerability Description
AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a valid code and bypass the intended second authentication factor, resulting in unauthorized account access.
The patch introduces per-user failed-OTP tracking, blocks verification after 30 failed attempts for one hour, clears the counter after a successful OTP verification, and provides administrator recovery actions to purge affected lockouts.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
过多认证尝试的限制不恰当
Vulnerability Title
ail project AIL Framework 授权问题漏洞
Vulnerability Description
ail project AIL Framework是ail project组织开源的一款服务器中间件软件。 ail project AIL Framework 0版本至6.8.0版本存在授权问题漏洞,该漏洞源于未限制双重身份验证(OTP)代码的失败尝试次数。攻击者完成密码验证阶段后,可无限次提交OTP猜测,通过暴力破解绕过第二重身份验证,导致未经授权的账户访问。以下版本受到影响:0版本至6.8.0版本。
CVSS Information
N/A
Vulnerability Type
N/A