漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)
Vulnerability Description
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_representer.rb and modules/costs/lib/api/v3/cost_entries/cost_entry_representer.rb without checking WorkPackage.visible or view_work_packages, allowing users with view_time_entries or view_cost_entries to read private work package subjects and ids. This issue is fixed in 17.6.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
OpenProject 信息泄露漏洞
Vulnerability Description
OpenProject是OpenProject组织开源的一个基于Web的项目管理软件。 OpenProject 17.6.0之前版本存在安全漏洞,该漏洞源于在渲染/api/v3/time_entries和/api/v3/cost_entries时未检查WorkPackage.visible或view_work_packages权限,可能导致拥有view_time_entries或view_cost_entries权限的用户读取私有工作包主题和ID。
CVSS Information
N/A
Vulnerability Type
N/A