当在 wolfSSHd 的 Windows 版本中使用密码或公钥认证时,在为一个已认证连接获取 Windows 登录令牌后,该令牌未能在获取后续连接的令牌之前被释放,从而导致连接之间的用户登录被污染(user login poisoning)。拥有服务器有效账户但权限较低的用户可利用此漏洞,强制以权限更高的用户身份进行登录。该漏洞由 wolfSSH 版本 1.4.15 中首次引入的 wolfSSHd Windows 端口带来,影响 1.4.15 至 1.5.0 的所有版本。wolfSSHd 的非 Windows 构
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet