漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Grav API Plugin before 1.0.10 Broken Access Control
Vulnerability Description
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Grav 授权问题漏洞
Vulnerability Description
Grav Grav是Grav组织开源的一个基于文件系统的无数据库内容管理系统。 Grav 1.0.10之前版本存在授权问题漏洞,该漏洞源于未限制对安全关键插件配置范围的写访问,允许具有api.config.write权限的经过身份验证的用户修改速率限制和CORS设置,可能导致攻击者禁用全站速率限制以进行凭据暴力破解攻击,并重新配置CORS策略以包含启用了凭据的攻击者控制来源。
CVSS Information
N/A
Vulnerability Type
N/A