Camunda 7.24.0 至 7.24.15 版本(不含 7.24.15)的管理 Web 应用程序的初始设置端点中存在不正确的授权漏洞。具体而言,SetupResource 在判断系统是否已完成初始设置时,仅统计 camunda-admin 组的直接成员,而未识别所有已配置的管理员账户。未认证的远程攻击者可利用此逻辑缺陷,调用用户创建设置端点,在 camunda-admin 组为空但系统实际已完全配置的情况下创建新的管理员账户,从而导致账户接管,并可能以引擎服务用户身份部署业务流程或执行脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet