漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization Boundaries
Vulnerability Description
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, but nothing verified that the supplied dashboardId belonged to that project, and getReportsByDashboardId in packages/db/src/services/reports.service.ts selects reports by dashboardId alone with no project scoping. An authenticated user could therefore pair a projectId from their own organization, which satisfies the middleware, with a dashboardId belonging to another organization and receive every report in that dashboard. A correctly scoped helper, listReportsCore, already existed in the same service file and resolves the dashboard through getDashboardById(dashboardId, projectId) before returning reports, but the router did not use it.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
OpenPanel 授权问题漏洞
Vulnerability Description
OpenPanel是OpenPanel公司开源的一款服务器管理面板软件。 OpenPanel 0a51b6805eed0b3da8376175acd5fa3d26819cb6之前版本存在授权问题漏洞,该漏洞源于report.list过程未验证dashboardId是否属于提供的projectId,可能导致经过身份验证的用户跨组织访问其他组织的报告。
CVSS Information
N/A
Vulnerability Type
N/A