漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Vulnerability Description
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Microsoft Kiota 路径遍历漏洞
Vulnerability Description
Microsoft Kiota是美国Microsoft公司的一款API平台生成工具。 Microsoft Kiota 1.29.1之前版本和1.30.0至1.34.0之前版本存在安全漏洞,该漏洞源于对OpenAPI描述文件中的文件引用验证不当,可能导致攻击者控制或篡改OpenAPI描述,从而包含或泄露清单包边界外的文件。
CVSS Information
N/A
Vulnerability Type
N/A