SecObserve 在 1.59.1 版本之前存在信息泄露漏洞。该漏洞位于 中,由于未能从 API 配置响应中移除 字段,导致只读权限的产品成员可以通过标准 REST 端点获取已配置的扫描器或集成服务账户的明文(解密后)basic-auth 密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SecObserve | SecObserve | 1.17.0 ~ 1.59.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet