One-API 对其两条“通道固定”(channel-pinning)路径中的其中一条实施了权限管控,而另一条没有。在 中,请求可以通过 API Key 的后缀或 URL 路径参数来指定特定的通道。其中,后缀方式只有在 校验通过后才会被处理,否则会拒绝调用者;而路径参数分支则直接从 取出通道标识,且完全未进行任何角色或权限检查。携带该参数的路由仅处于 Token 认证层之后,因此任何持有有效 API Token 的账户都能访问它。该通道标识随后被传递给分发器(distributor),分发器通过整数标识加载对应通道
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| songquanpeng | one-api | ≤ 0.6.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| songquanpeng | one-api | 0 ~ 0.6.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet