Anchore Enterprise是Anchore公司的一款容器镜像安全分析与合规管理的平台。 Anchore Enterprise 5.11.0版本至5.27.1版本和6.0.0版本存在权限许可和访问控制问题漏洞,该漏洞源于用户管理API存在不当的权限提升问题,可能导致经过身份验证的攻击者通过API调用修改用户权限,从而获取额外资源和操作的访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Anchore | Anchore Enterprise | 5.11.0< 5.27.2 |
affected |
6.0.0< 6.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Anchore | Anchore Enterprise | 5.11.0 ~ 5.27.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet