Alluxio 的 S3 REST 代理服务在其默认配置下未能验证 AWS Signature Version 4(签名版本 4)的签名,这使得未经身份验证的攻击者可以伪装用户身份。攻击者可以从未签名的 Authorization 头部中提取用户名,并冒充任何用户(包括服务账户),从而读取、写入和删除任意数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet