Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
Vulnerability Description
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
milvus-io milvus 授权问题漏洞
Vulnerability Description
milvus-io milvus是milvus-io组织的一款消息队列中间件。 milvus-io milvus 2.6.22及之前版本和3.0.0版本存在授权问题漏洞,该漏洞源于管理服务器未受保护的/management/stop端点可绕过REST API认证,攻击者通过发送特制HTTP GET请求并提供role参数关闭服务组件,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A