漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CVE-2026-9092
Vulnerability Description
Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a EmailVerified field. An attacker can supply an unverified email claim from an upstream provider to take over accounts that use the same email address.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Casdoor 安全漏洞
Vulnerability Description
Casdoor是Casdoor开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor 2.362.0及之前版本存在安全漏洞,该漏洞源于未验证的电子邮件绑定问题,可能导致账户接管,因为getExistUserByBindingFunction函数通过电子邮件匹配用户而未检查上游提供商中的email_verified声明,idp.UserInfo结构甚至不包含EmailVerified字段,攻击者可以从上游提供商提供未经验证的电子邮件声明来接管使用相同电子邮件地址的账户。
CVSS Information
N/A
Vulnerability Type
N/A