该描述涉及的是 Gonic(一个音乐元数据/媒体库管理工具)的一个安全漏洞。以下是中文翻译: Gonic 在 0.22.0 之前的版本中,在 端点未能正确验证管理员权限,导致任何已认证的用户都能触发媒体库重新扫描。攻击者可以反复调用 端点,强制系统执行 CPU 和 I/O 密集型文件系统操作,从而在多用户实例上造成拒绝服务(DoS)。 --- 关键点解析: 漏洞类型:权限验证缺失(Insufficient Permission Checks) 影响:已认证普通用户可触发高负载操作 后果:CPU/I/O 资源耗尽 →
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet