漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
Vulnerability Description
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
milvus-io milvus 授权问题漏洞
Vulnerability Description
milvus-io milvus是milvus-io组织的一款消息队列中间件。 milvus-io milvus 2.6.22及之前版本和3.0.0版本存在授权问题漏洞,该漏洞源于管理服务器未受保护的/management/stop端点可绕过REST API认证,攻击者通过发送特制HTTP GET请求并提供role参数关闭服务组件,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A