Crawlab 版本 0.6.3 及以下版本在生成 JWT 令牌时使用了一个硬编码的 HMAC-SHA256 密钥进行签名,且该密钥无法通过配置文件或环境变量进行覆盖。未认证的攻击者可以利用此缺陷伪造有效的管理员令牌,从而访问管理接口并在 Worker 节点上执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| crawlab-team | crawlab | ≤ 0.6.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| crawlab-team | crawlab | 0 ~ 0.6.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet