漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenPanel report.get Returns Any Report by Identifier Without Checking Project Access
Vulnerability Description
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries a projectId or organizationId key, so an input consisting of a reportId alone passed through unchecked, and getReportById in packages/db/src/services/reports.service.ts performs a findUnique on the report id with no project scoping. Any authenticated user could therefore read the full configuration of any saved report on the instance, including the owning projectId, event series, filters, breakdowns and formulas, by supplying its identifier. The adjacent update, delete and duplicate procedures resolve the report first and check getProjectAccess against the report's own projectId, so the omission was specific to this procedure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
OpenPanel 授权问题漏洞
Vulnerability Description
OpenPanel是OpenPanel公司开源的一款服务器管理面板软件。 OpenPanel 0a51b6805eed0b3da8376175acd5fa3d26819cb6之前版本存在授权问题漏洞,该漏洞源于packages/trpc/src/routers/report.ts中的report.get过程仅接受reportId并直接查询报告,未验证项目访问权限,导致任何已认证用户可通过提供报告标识符读取任意报告的完整配置。
CVSS Information
N/A
Vulnerability Type
N/A