在 tsi-coop tsi-dpdp-cms 中确定存在一个漏洞,影响版本最高至 0.5.0。该问题影响 Admin Console/DPO Compliance Console 组件中 web.xml 文件的某些未知功能。执行特定的操作可能导致认证缺失(missing authentication)。该攻击可以远程触发,且漏洞利用方式已公开披露,可能被利用。将组件升级到 0.5.1 版本可解决此问题。建议对受影响组件进行升级。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tsi-coop | tsi-dpdp-cms | 0.1 |
affected |
0.2 |
affected | ||
0.3 |
affected | ||
0.4 |
affected | ||
0.5.0 |
affected | ||
0.5.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tsi-coop | tsi-dpdp-cms | 0.1 |
cpe:2.3:a:tsi-coop:tsi-dpdp-cms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84841 | 7.3 HIGH | tsi-coop tsi-dpdp-cms client-side enforcement of server-side security |
| CVE-2026-84840 | 6.5 MEDIUM | tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authenticat |
No comments yet