OpenRemote 在 1.28.0 之前的版本中,其通知 REST API 存在一个跨 Realm(领域/租户)的信息泄露漏洞。该漏洞允许特定 Realm 的租户管理员读取所有租户已发送的通知,包括通知消息正文。拥有单个 Realm 中 权限的攻击者,可以通过向通知端点发送一个无参数的 GET 请求,从而获取来自所有 Realm 的敏感通知元数据和消息内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openremote | openremote | < 1.28.0 |
affected |
1.28.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openremote | openremote | 0 ~ 1.28.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet