Jpom 在 2.11.12 及更早版本中,在 端点解析 repositoryId 时未能正确校验工作空间(workspace)的所有权,导致已认证用户能够访问其他工作空间中的仓库。攻击者可以提交来自不同工作空间的仓库标识符,从而枚举仓库是否存在、判断仓库类型,并借助其他工作空间存储的凭据执行 命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet