Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep
Vulnerability Description
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. Attackers can submit POST requests to the decay sweep endpoint with ttl_seconds=0 to expire facts across all tenants, or use dry_run to obtain cross-tenant fact counts and existence information.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
eidetic-labs stigmem 授权问题漏洞
Vulnerability Description
eidetic-labs stigmem是eidetic-labs组织的一款威胁情报网络产品。 eidetic-labs stigmem 0.9.0a12之前版本存在授权问题漏洞,该漏洞源于decay sweep端点存在对象级授权失效问题,可能允许具有单个租户写凭据的已认证攻击者执行影响所有租户的decay操作,或通过提交ttl_seconds=0的POST请求过期所有租户的事实,以及使用dry_run获取跨租户事实计数和存在信息。
CVSS Information
N/A
Vulnerability Type
N/A