Devtron 2.2.0 及更早版本在 的 GET 接口上未执行适当的授权检查,导致经过身份验证的用户能够获取管理员 API 令牌。任何拥有已认证账户的攻击者都可以通过传入任意项目、环境和应用参数来查询该端点,从而获取明文超级管理员 JWT 令牌,进而获得对整个平台的完全控制权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| devtron-labs | devtron | 0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet