Arcane是Arcane公司开源的一款功能多样的软件产品。 Arcane 2.0.0之前版本存在授权问题漏洞,该漏洞源于对模板操作限制不当,允许默认用户角色账户创建、修改和删除compose模板,攻击者可注入具有特权设置或主机路径挂载的恶意容器配置,在管理员部署时以管理权限执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getarcaneapp | arcane | 1.19.1< 2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getarcaneapp | arcane | 1.19.1 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet