漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is Enabled
Vulnerability Description
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete monitor objects from server/src/controllers/statusPageController.ts. The response includes the secret field used by HttpProvider.ts as an HTTP Authorization credential, even though BaseStatusPage.tsx does not display that value, allowing visitors to extract credentials from the JSON response and use them against monitored services. This issue is fixed in version 3.9.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
BlueWave Labs Checkmate 信息泄露漏洞
Vulnerability Description
BlueWave Labs Checkmate是BlueWave Labs组织的一款监控与运维管理工具。 BlueWave Labs Checkmate 3.3.0版本至3.9.2之前版本存在安全漏洞,该漏洞源于启用全局showURL设置导致未经身份验证的GET /api/v1/status-page/:url端点返回完整的监视器对象,响应中包含用作HTTP Authorization凭据的secret字段,可能导致访问者提取凭据并用于受监控服务。
CVSS Information
N/A
Vulnerability Type
N/A