漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
potpie through 2.0.0 Missing Ownership Check via code-changes sync
Vulnerability Description
potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
potpie.ai potpie 授权问题漏洞
Vulnerability Description
potpie.ai potpie是potpie.ai组织的一个基于代码库生成定制AI代理的平台。 potpie.ai potpie 2.0.0及之前版本存在授权问题漏洞,该漏洞源于未验证POST /conversations/{conversation_id}/code-changes/sync端点上的用户所有权,可能导致已认证攻击者通过提供其他用户的会话ID写入任意文件更改,从而未经授权修改待处理更改。
CVSS Information
N/A
Vulnerability Type
N/A