漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC
Vulnerability Description
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Cybersecurity and Infrastructure Security Agency Malcolm 授权问题漏洞
Vulnerability Description
Cybersecurity and Infrastructure Security Agency Malcolm是Cybersecurity and Infrastructure Security Agency组织的一款网络流量与日志分析平台。 Cybersecurity and Infrastructure Security Agency Malcolm 26.07.0之前版本存在授权问题漏洞,该漏洞源于Nginx OpenResty Lua层中的角色访问控制评估原始未标准化的request_uri,而
CVSS Information
N/A
Vulnerability Type
N/A