Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Anubis: Policy bypass via client controlled X-Original-URI header
Vulnerability Description
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client-controlled X-Original-URI header before matching r.URL.Path, allowing an HTTP client to match default data/common/keep-internet-working.yaml ALLOW rules such as ^/\.well-known/.*$ and bypass the Anubis challenge. This issue is fixed in version 1.26.0-pre1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
TecharoHQ Anubis 权限许可和访问控制问题漏洞
Vulnerability Description
TecharoHQ Anubis是TecharoHQ公司开源的一款认证和授权服务器软件。 TecharoHQ Anubis 1.22.0版本至1.26.0-pre1之前版本存在权限许可和访问控制问题漏洞,该漏洞源于lib/policy/checker.go PathChecker.Check()信任客户端控制的X-Original-URI标头,导致HTTP客户端可绕过Anubis验证。
CVSS Information
N/A
Vulnerability Type
N/A