脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Apps Manager sends tokens to Spring apps via HTTP
脆弱性説明
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent requests via unsecured http. An adjacent unauthenticated user could eavesdrop on the network traffic and gain access to the unencrypted token allowing the attacker to read the type of access a user has over an app. They may also modify the logging level, potentially leading to lost information that would otherwise have been logged.
CVSS情報
N/A
脆弱性タイプ
敏感数据的明文传输
脆弱性タイトル
Pivotal Application Service Pivotal Apps Manager 访问控制错误漏洞
脆弱性説明
Pivotal Software Application Service(PAS)是美国Pivotal Software公司的一套应用程序管理软件。Apps Manager是其中的一个应用程序管理器。 Pivotal Application Service中的Pivotal Apps Manager存在安全漏洞。攻击者可利用该漏洞监听网络流量并获取未加密的令牌。以下产品及版本受到影响:Pivotal Application Service 2.3.16之前的2.3.x版本,2.4.12之前的2.4.x版本
CVSS情報
N/A
脆弱性タイプ
N/A