lamp-cloud 5.10.0 及更早版本对路径模式 进行了白名单设置,允许匿名用户访问,从而使未经身份验证的攻击者能够读取服务器完整的 JVM 系统属性映射。攻击者可以向 发送 POST 请求,获取敏感信息,包括 JVM 类路径、文件系统路径、操作系统详细信息以及启动密钥等。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dromara | lamp-cloud | 0 ~ 5.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet