漏洞概述 漏洞标题:[Bug] [dbgpt-app] Unauthenticated path-traversal arbitrary file write via the user_id header in the python file-upload endpoint #3104 漏洞编号:#3104 状态:已关闭 创建者:geo-chen 创建时间:Jun 12 影响范围 操作系统:Linux Python版本:3.11 DB-GPT版本:main 相关场景: - Chat Data - Chat Excel - Chat DB - Chat Knowledge - Model Management - Dashboard - Plugins 修复方案 修复提交: - 提交1: - 提交者:eosphoros - 提交链接:eosphoros/wDB-GPT - 提交2: - 提交者:eosphoros - 提交链接:eosphoros/wDB-GPT 其他信息 标签:Waiting for reply, bug 类型:No type 项目:No projects 里程碑:No milestone 关系:None yet 参与者: - LEEKIYOON-SEC - 其他参与者(具体名称未显示) 补充说明 安装信息: - Installation From Source - Docker Installation - Docker Compose Installation - Cluster Installation 备注 该漏洞涉及通过 头部的未认证路径遍历,导致任意文件写入。 修复方案包括验证 以防止路径遍历攻击。