Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine
Vulnerability Description
stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count queries and _get_quarantined_fact in routes/quarantine.py lacked a tenant_id predicate and the garden lookup was not tenant-scoped, allowing a tenant administrator with only a plain tenant write capability to list, read, and admit or reject quarantined facts belonging to other tenants via the /v1/quarantine endpoints. Default single-tenant deployments are not affected.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
eidetic-labs stigmem 授权问题漏洞
Vulnerability Description
eidetic-labs stigmem是eidetic-labs组织的一款威胁情报网络产品。 eidetic-labs stigmem 0.9.0a12之前版本存在授权问题漏洞,该漏洞源于隔离审查端点存在对象级授权失效(跨租户BOLA),list/count查询和_get_quarantined_fact缺少tenant_id谓词且garden查找未按租户限定,可能导致具有普通租户写入权限的租户管理员越权访问其他租户的隔离事实。
CVSS Information
N/A
Vulnerability Type
N/A