Yao 在 v1.0.0-rc22 及更早版本中,虽然实现了身份认证,但未能对 端点进行授权控制,导致任何已登录的用户都可以读取完整的团队记录。攻击者可以通过提供已知的团队标识符,获取敏感的团队数据(包括名称、描述、所有者信息和设置),而无需验证其是否为该团队的成员。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet