djehuty 是由 4TU.ResearchData 开发的一个研究数据仓库系统。在版本 26.3.2 之前,未经身份验证的攻击者可以通过三个不同的参数向搜索/列表查询中注入 SPARQL 代码。由于受影响的查询为只读(SELECT)类型,该漏洞不会向数据存储中写入数据,但允许攻击者执行以下操作: 跨图数据泄露——例如,通过 UNION 操作引入请求原本未授权访问的 RDF 图中的三元组(如存储在 RDF 存储中的草稿、私有或内部数据); 拒绝服务攻击——通过执行高开销或格式错误的查询,占用 SPARQL 后端/
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 4TUResearchData | djehuty | < 26.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 4TUResearchData | djehuty | < 26.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet