Onyx 4.6.6 未能正确限制对存储在 中的自定义工具凭据的访问,使得任何经过身份验证的用户都可以读取由管理员定义的 API 密钥。拥有基础身份验证权限的攻击者可以通过调用 或 端点,获取明文格式的授权头(authorization headers)以及第三方 API 凭据,并直接使用这些凭据访问上游 API。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| onyx-dot-app | onyx | ≤ 4.6.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| onyx-dot-app | onyx | 0 ~ 4.6.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet