在 OpenStack Zaqar 22.0.2 之前的版本中,WSGI 传输模块对 URL-Signature 请求头处理不当。攻击者只需发送一个带有空 URL-Signature 头部的请求,即可绕过 Keystone 身份验证和预签名 URL 验证。前提是攻击者知道目标项目的 UUID,且未进行身份认证,从而获得对该项目的队列、消息、声明(claims)和订阅(subscriptions)的读取、枚举、创建和删除权限。此外,若攻击者进一步获取管理员角色,还可能在启用 admin_mode 的部署环境中执行管理
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet