Tina 是一个无头内容管理系统。在 next-tinacms-s3 23.0.4、next-tinacms-dos 23.0.4、next-tinacms-azure 14.0.4 以及 next-tinacms-cloudinary 26.0.4 版本之前,Tina 的官方生产媒体适配器未强制实施操作者配置媒体根目录(mediaRoot),直接将攻击者控制的对象键(object keys)传递给存储 SDK 的上传和删除操作。 具体而言,在 文件中, 函数接受 作为签名 PutObject URL 的输入,而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tinacms | next-tinacms-azure | < 14.0.4 |
affected |
| tinacms | next-tinacms-cloudinary | < 26.0.4 |
affected |
| tinacms | next-tinacms-dos | < 23.0.4 |
affected |
| tinacms | next-tinacms-s3 | < 23.0.4 |
affected |
| tinacms | tinacms | < 23.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tinacms | tinacms | < 23.0.4 | - |
|
| tinacms | next-tinacms-s3 | < 23.0.4 | - |
|
| tinacms | next-tinacms-dos | < 23.0.4 | - |
|
| tinacms | next-tinacms-azure | < 14.0.4 | - |
|
| tinacms | next-tinacms-cloudinary | < 26.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet