superplanehq superplane是superplanehq组织的一款企业级项目协作平台。 superplanehq superplane 0.27.0之前版本存在授权问题漏洞,该漏洞源于CanvasService gRPC处理程序存在对象级授权缺陷,允许已认证的具有查看者权限的用户通过提供任意canvas或queue UUIDs跨组织访问资源,导致攻击者可以读取跨租户执行历史和包含敏感秘密的事件载荷,向受害组织写入队列项和canvas事件,删除任意canvas,并跨租户边界破坏自动化工作流。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| superplanehq | superplane | < 0.27.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| superplanehq | superplane | 0 ~ 0.27.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet