HyperDX 1.10.1 及更早版本未能在团队管理端点中正确实施基于角色的访问控制,使得任何团队成员都能执行管理操作。攻击者通过向 PATCH /team/apiKey、PATCH /team/name 和 DELETE /team/member 端点发送请求,可以删除团队成员(包括所有者)、轮换 API 密钥以及重命名团队。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet