漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
Vulnerability Description
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
julep-ai Julep 授权问题漏洞
Vulnerability Description
julep-ai Julep是julep-ai组织开源的一个机器学习与人工智能平台。 julep-ai Julep存在授权问题漏洞,该漏洞源于get_execution_details端点存在不安全的直接对象引用,导致已认证租户可以读取其他租户的执行数据。
CVSS Information
N/A
Vulnerability Type
N/A