漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Writes
Vulnerability Description
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the userId scope that sibling methods apply, and findMessagePlugin reads back by id alone. Reachable via the corresponding tRPC message procedures, an authenticated user who knows another user's message identifier can overwrite that victim's plugin tool-call metadata, plugin state/error, text-to-speech and translation records on the same instance, and the tampered content is served back to the victim. Exploitation requires knowledge of the victim's non-enumerable message identifier.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
LobeHub LobeChat 授权问题漏洞
Vulnerability Description
LobeHub是LobeHub团队开源的一个全平台AI对话框架。 LobeHub LobeChat 2.2.9及之前版本存在授权问题漏洞,该漏洞源于MessageModel中对象级授权机制失效,updateMessagePlugin、updatePluginState、updatePluginError、updateTTS和updateTranslate方法仅依靠消息id过滤目标行,导致已认证用户如果知道其他用户的消息标识符,能够覆盖该受害者的插件工具调用元数据、插件状态/错误、文本转语音和翻译记录。
CVSS Information
N/A
Vulnerability Type
N/A