漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
Vulnerability Description
immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can demote the album owner to editor and promote themselves to owner in sequential requests, gaining full control including deletion and eviction capabilities.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
immich-app immich 授权问题漏洞
Vulnerability Description
immich是Immich团队开源的一个高性能自托管照片和视频管理解决方案。 immich-app immich 3.0.3之前版本存在授权问题漏洞,该漏洞源于PUT /albums/:id/user/:userId端点存在访问控制失效,允许共享专辑编辑者修改成员角色,可能导致具有编辑权限的攻击者将专辑所有者降级为编辑并自提升为所有者,从而获得包括删除和驱逐能力的完全控制。
CVSS Information
N/A
Vulnerability Type
N/A