漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink
Vulnerability Description
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL window to redirect the raw os.Remove call to an out-of-scope target, bypassing ScopedFs scope guards and Perm.Delete checks.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
File Browser 后置链接漏洞
Vulnerability Description
File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.63.19之前版本存在后置链接漏洞,该漏洞源于TUS上传缓存逐出机制中的越界文件删除漏洞,攻击者可通过符号链接替换祖先目录绕过ScopedFs范围检查和Perm.Delete校验,导致仅具有Create权限的认证用户能够删除其范围之外的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A