OpenCVE 在 3.1.0 之前的版本中,未能正确地将“组织”API 端点限制在令牌所属的范围内,而是返回了令牌创建者的成员身份关系。攻击者若持有组织范围的令牌,即可列出并获取其创建者所属的所有组织,从而绕过了预期的令牌隔离边界。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet