Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth
Vulnerability Description
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
eidetic-labs stigmem 授权问题漏洞
Vulnerability Description
eidetic-labs stigmem是eidetic-labs组织的一款威胁情报网络产品。 eidetic-labs stigmem 0.9.0a2之前版本存在授权问题漏洞,该漏洞源于非回环部署中禁用身份验证,可能导致未经身份验证的攻击者以匿名身份执行读取、写入和联合操作。
CVSS Information
N/A
Vulnerability Type
N/A