目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-62382— pglombardo PasswordPusher 授权问题漏洞

一分钟漏洞结论

影响对象
pglombardo PasswordPusher
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

pglombardo PasswordPusher是pglombardo个人开发者的一款密码推送工具。 pglombardo PasswordPusher v1.45.11版本至v2.9.5版本存在授权问题漏洞,该漏洞源于推送删除逻辑中的授权不当,匿名创建的推送在所有权检查时@push.user与current_user均为nil,导致检查通过,攻击者仅凭secret URL即可永久删除匿名推送。

CVSS 6.9 · Medium EPSS 1.12% · P65

公开利用映射 1

影响版本矩阵 2

厂商产品 版本范围状态
pglombardo PasswordPusher < 2.9.6 affected
2.9.6 unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-62382 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison
来源: CVE Program / CVE List V5
Vulnerability Description
PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the deletable_by_viewer restriction is never enforced. An attacker who knows only the secret URL can permanently delete an anonymous push even when the creator disabled viewer deletion and even without the passphrase. Only deployments that allow anonymous pushes (the default) are affected. The issue is fixed in v2.9.6.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
来源: CVE Program / CVE List V5
Vulnerability Title
pglombardo PasswordPusher 授权问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
pglombardo PasswordPusher是pglombardo个人开发者的一款密码推送工具。 pglombardo PasswordPusher v1.45.11版本至v2.9.5版本存在授权问题漏洞,该漏洞源于推送删除逻辑中的授权不当,匿名创建的推送在所有权检查时@push.user与current_user均为nil,导致检查通过,攻击者仅凭secret URL即可永久删除匿名推送。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
pglombardo PasswordPusher 0 ~ 2.9.6 -

二、漏洞 CVE-2026-62382 的公开POC

# POC 描述 源链接 神龙链接
1 PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-62382.yaml POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-62382 的情报信息

请登录查看更多情报信息。

CVE-2026-62382 厂商安全公告 (1)

CVE-2026-62382 安全博客文章 (1)

CVE-2026-62382 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-62382

暂无评论


发表评论