Kibana 中存在用户可控键绕过授权(CWE-639)漏洞,可能导致通过访问未被访问控制列表(ACL)充分约束的功能(CAPEC-1)来执行未授权的数据修改。在某些条件下,已认证的用户可以引用其他用户的 AI 助手会话标识符,从而访问或修改不属于他们自己的会话。成功利用该漏洞需要获取一个难以猜测的标识符。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet