pglombardo PasswordPusher是pglombardo个人开发者的一款密码推送工具。 pglombardo PasswordPusher v1.45.11版本至v2.9.5版本存在授权问题漏洞,该漏洞源于推送删除逻辑中的授权不当,匿名创建的推送在所有权检查时@push.user与current_user均为nil,导致检查通过,攻击者仅凭secret URL即可永久删除匿名推送。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| pglombardo | PasswordPusher | < 2.9.6 |
affected |
2.9.6 |
unaffected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| pglombardo | PasswordPusher | 0 ~ 2.9.6 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-62382.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论