Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bastillion Authentication Bypass via Path-Prefix Routing Mismatch
Vulnerability Description
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用候选路径或通道进行的认证绕过
Vulnerability Title
Loophole Bastillion 授权问题漏洞
Vulnerability Description
Loophole Bastillion是Loophole公司的一款集中式SSH访问与审计的Web管理平台。 Loophole Bastillion 5.1.0及之前版本存在授权问题漏洞,该漏洞源于未能正确验证控制器调度器中的请求URI路径,可能导致未经身份验证的攻击者通过向请求添加任意路径段绕过身份验证过滤器,访问管理控制器以读取用户列表、创建管理员账户、注册受管系统,从而控制受管机群的SSH访问。
CVSS Information
N/A
Vulnerability Type
N/A