在 cleverbrush 框架中(最高至 4.4.0 版本)发现了一个漏洞,该漏洞影响 文件中的 函数。此问题可导致对对象原型属性的修改缺乏适当控制,从而引发不安全的对象属性篡改。远程攻击者可利用该漏洞进行远程攻击。目前,该漏洞的利用方式已公开,可能被恶意利用。建议升级至 4.4.1 版本以修复此问题。补丁标识为 810398c1308c500c3b8b6af380b5a89371389327。请立即升级受影响的组件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cleverbrush | deep | 4.0 |
affected |
4.1 |
affected | ||
4.2 |
affected | ||
4.3 |
affected | ||
4.4.0 |
affected | ||
4.4.1 |
unaffected | ||
| cleverbrush | framework | 4.0 |
affected |
4.1 |
affected | ||
4.2 |
affected | ||
4.3 |
affected | ||
4.4.0 |
affected | ||
4.4.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cleverbrush | framework | 4.0 |
cpe:2.3:a:cleverbrush:framework:*:*:*:*:*:*:*:*
|
|
| cleverbrush | deep | 4.0 |
cpe:2.3:a:cleverbrush:deep:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet