Semaphore(一款持续集成/持续交付平台)在版本 2.19.12 及之前存在一个漏洞:其 中间件在处理请求时,对 GET 和 HEAD 请求免除了项目资源权限检查。因此,拥有“访客”(guest)或“任务运行器”(task_runner)角色的攻击者,可以通过向环境端点发送 GET 请求,读取到所有项目的配置环境,其中包括明文存储的秘密(secrets)、凭证和密码等信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| semaphoreui | semaphore | 0 ~ 2.19.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet