在 tsi-coop 的 tsi-dpdp-cms 组件中,版本 0.5.0 及更早版本中发现了一个安全缺陷。该漏洞影响未知代码部分,其核心问题是:客户端对服务器端的安全机制进行了强制执行(client-side enforcement of server-side security),导致安全风险。此攻击可以远程发起。该漏洞的利用代码(exploit)已公开,可能被用于实施攻击。升级至版本 0.5.1 可解决此问题。建议升级受影响的组件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tsi-coop | tsi-dpdp-cms | 0.1 |
affected |
0.2 |
affected | ||
0.3 |
affected | ||
0.4 |
affected | ||
0.5.0 |
affected | ||
0.5.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tsi-coop | tsi-dpdp-cms | 0.1 |
cpe:2.3:a:tsi-coop:tsi-dpdp-cms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84840 | 6.5 MEDIUM | tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authenticat |
| CVE-2026-84839 | 5.3 MEDIUM | tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authentication |
No comments yet