漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection
Vulnerability Description
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path patched by node/lib/asterisk-manager-patch.js, allowing arbitrary commands to execute as the asterisk service user. This issue is fixed in version 17.0.9.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
授权机制缺失
Vulnerability Title
FreePBX 授权问题漏洞
Vulnerability Description
FreePBX是FreePBX团队开源的一款基于Web的电话交换系统。 FreePBX 17.0.9之前版本存在授权问题漏洞,该漏洞源于UCP Node服务器中Socket.IO 4中间件仅应用于默认命名空间,导致未经身份验证的客户端可连接自定义命名空间并通过Asterisk Manager Interface发送包含回车或换行的特制事件值,可能导致任意命令以asterisk服务用户身份执行。
CVSS Information
N/A
Vulnerability Type
N/A