thehive-project TheHive是thehive-project组织的一款安全事件响应平台。 thehive-project TheHive 4.1.24及之前版本存在授权问题漏洞,该漏洞源于附件下载端点存在对象级授权缺陷,允许任何通过内容哈希标识符提供内容的认证用户访问其他组织的附件,攻击者可利用AttachmentSrv.visible中缺失的组织范围授权检查来下载任意附件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TheHive-Project | TheHive | ≤ 4.1.24 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TheHive-Project | TheHive | 0 ~ 4.1.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet