Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Velociraptor collect_client() Permissions Bypass
Vulnerability Description
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider.
This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Rapid7 velociraptor 授权问题漏洞
Vulnerability Description
Rapid7 Velociraptor是美国Rapid7公司开源的一款终端安全与响应工具。 Rapid7 velociraptor 0.77.2之前版本存在授权问题漏洞,该漏洞源于授权提供程序重置导致权限检查未正确执行,可能允许用户从analyst角色提升至investigator角色。
CVSS Information
N/A
Vulnerability Type
N/A