漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete
Vulnerability Description
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
OpenChoreo Backstage Plugins 授权问题漏洞
Vulnerability Description
OpenChoreo Backstage Plugins是openchoreo组织的一系列扩展软件功能的插件组件。 OpenChoreo Backstage Plugins 1.0.4之前版本、1.1.4之前版本和1.2.1之前版本存在授权问题漏洞,该漏洞源于硬编码禁用默认认证策略,可能导致未经身份验证的攻击者读取目录数据、读取scaffolder日志以及创建或删除目录位置。
CVSS Information
N/A
Vulnerability Type
N/A