Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
New API: Admin can reset passkeys for same-level or higher-privileged users
Vulnerability Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to remove a passkey from a same-level or higher-privileged account, including a root account. This issue is fixed in version 1.0.0-rc.7.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制缺失
Vulnerability Title
QuantumNous New API 授权问题漏洞
Vulnerability Description
QuantumNous New API是QuantumNous个人开发者的一个LLM网关和AI资产管理系统。 QuantumNous New API 0.9.1.3至1.0.0-rc.7之前版本存在授权问题漏洞,该漏洞源于controller/passkey.go中的AdminResetPasskey对DELETE /api/user/:id/reset_passkey缺少canManageTargetRole授权检查,可能导致低权限管理员删除同级别或更高级别账户(包括root账户)的passkey。
CVSS Information
N/A
Vulnerability Type
N/A