Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id}
Vulnerability Description
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid GitHub token to invoke bare KV-store operations such as projects.Fetch and project.Delete against any project ID to achieve cross-tenant project takeover.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Taubyte 授权问题漏洞
Vulnerability Description
Taubyte是Taubyte组织开源的一款区块链云计算平台。 Taubyte 1.1.10版本存在授权问题漏洞,该漏洞源于services/auth HTTP服务中的GitHubTokenHTTPAuth中间件仅验证GitHub OAuth令牌有效性而未验证目标项目所有权或访问权限,可能导致任意已认证用户通过任意项目ID读取或永久删除其他租户项目,造成跨租户项目接管。
CVSS Information
N/A
Vulnerability Type
N/A