Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication
Vulnerability Description
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Pangolin 授权问题漏洞
Vulnerability Description
Pangolin是Pangolin组织开源的一个代理服务器软件。 Pangolin 1.20.0及之前版本存在授权问题漏洞,该漏洞源于授权验证不当,在authWithAccessToken.ts处理程序中调用verifyResourceAccessToken()时未传递目标resourceId,导致经过身份验证的远程攻击者可重用针对不同资源颁发的访问令牌,从而认证到任意组织的任意资源。
CVSS Information
N/A
Vulnerability Type
N/A