在 kvcache-ai mooncake 版本 0.3.12 及 0.3.13.post1 之前版本中,发现了一个安全漏洞。该漏洞影响了 RPC 路径处理程序(RPC Path Handler)组件中的 UnmountSegment 函数。通过操纵参数 client_id/segment_id,可导致授权绕过(Authorization Bypass)。该攻击支持远程利用。此漏洞的利用方法已公开披露,且可能被恶意利用。供应商已提前获知此漏洞的披露信息,但未作出任何回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kvcache-ai | mooncake | 0.3.0 |
affected |
0.3.1 |
affected | ||
0.3.2 |
affected | ||
0.3.3 |
affected | ||
0.3.4 |
affected | ||
0.3.5 |
affected | ||
0.3.6 |
affected | ||
0.3.7 |
affected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | mooncake | 0.3.0 |
cpe:2.3:a:kvcache-ai:mooncake:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet