在 grimmory-tools grimmory 3.3.3/3.4.1 及更早版本中检测到一个安全漏洞。受影响的是组件“设置 API 端点”中文件 里的函数 。这种操纵会导致授权不正确。该攻击可远程发起。该漏洞利用方式已公开披露,可能会被利用。补丁名称为 2b66ca6df810f6b512e030b54c16b9fbe318f17。建议应用此补丁以解决该问题。PR #2558(合并为 53abc8b)将 OIDC 密钥移到了独立的设置项中,但其本身并未限制 接口。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grimmory-tools | grimmory | 3.3.0 |
cpe:2.3:a:grimmory-tools:grimmory:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet