漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation
Vulnerability Description
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in controller/model/enrollment_manager.go verifies only that the target identity exists without performing authorization checks binding the caller to the target identity. Attackers can redeem the resulting one-time token through the unauthenticated client API enrollment endpoint to obtain a client certificate authenticating as the targeted admin identity, yielding full administrative control of the controller and the zero-trust overlay it manages.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
OpenZiti 授权问题漏洞
Vulnerability Description
OpenZiti是OpenZiti组织开源的一款零信任网络访问平台。 OpenZiti 2.0.0及之前版本存在授权问题漏洞,该漏洞源于ApplyCreate函数仅验证目标身份存在而未执行授权检查,导致具有注册管理权限的经过身份验证的非管理员身份可为任意身份创建注册,进而通过未验证客户端API注册端点获取目标管理员身份认证证书,获得控制器的完全管理权限。
CVSS Information
N/A
Vulnerability Type
N/A