Soft Serve 0.7.1 至 0.11.6 版本未将 Git LFS 锁查询限定在特定仓库范围内,导致经过身份验证的用户能够读取其无权访问的仓库中的锁元数据。拥有任意一个仓库写权限的攻击者可以在全局范围内枚举锁 ID,从而获取私有仓库中被锁定文件的路径、用户名以及锁定时间戳。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| charmbracelet | soft-serve | 0.7.1 ~ 0.12.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet