Peppermint(版本 0.5.5 及之前版本)存在一个授权绕过漏洞,位于 端点。该漏洞允许已认证的 attacker 通过提供任意用户 ID 来删除任意用户的会话。由于该端点未执行任何授权检查以验证调用者是否为目标账户的所有者,攻击者可以强制注销任意用户(包括管理员)的会话,只需调用 logout 处理器并传入其他用户的 ID 即可。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Peppermint-Lab | peppermint | ≤ 0.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Peppermint-Lab | peppermint | 0 ~ 0.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet