PasswordPusher 2.11.1 之前的版本中存在一个“检查时”到“使用时”(TOCTOU)的竞态条件,出现在视图限制(view limit enforcement)逻辑中,这使得未认证的攻击者能够绕过 限制。攻击者可以向 端点发送并发请求,从而在视图计数被递增、推送内容过期之前,多次访问一次性密钥(one-time secrets)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pglombardo | PasswordPusher | 0 ~ 2.11.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet