在 StackStorm 的 st2 组件(版本 3.9.0 及更早版本)中已发现一个安全弱点。该问题影响文件 中名为 的函数,涉及 NoOp RBAC 后端组件。由于对参数 的处理不当,导致权限管理存在缺陷。该漏洞可被远程利用,且已有公开的利用方式可供攻击者使用。此前发布的公告 CVE-2022-44009 是针对同一漏洞点的后续报告,但当前问题与之不同:本漏洞不依赖 Jinja RBAC,并且影响的是默认安装配置(RBAC 被禁用的情况)。项目方虽已通过问题报告提前获知此问题,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| StackStorm | st2 | 3.0 |
affected |
3.1 |
affected | ||
3.2 |
affected | ||
3.3 |
affected | ||
3.4 |
affected | ||
3.5 |
affected | ||
3.6 |
affected | ||
3.7 |
affected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| StackStorm | st2 | 3.0 |
cpe:2.3:a:stackstorm:st2:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet