Nango 0.71.6 版本之前的版本存在一个认证缺失漏洞,该漏洞位于 runner 的 tRPC 服务器中,允许未经身份验证的攻击者通过调用暴露的 start 过程执行任意 JavaScript 代码。拥有 runner 端口网络访问权限的攻击者可以向未认证的 start 过程发送请求,绕过未强制执行的 RUNNER_SECRET_KEY 环境变量,从而在 runner 进程中实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet