Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SolarWinds Observability Self-Hosted Deserialization of Untrusted Data Local Privilege Escalation Vulnerability
Vulnerability Description
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account and local access to the host server.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
SolarWinds Observability Self-Hosted 代码问题漏洞
Vulnerability Description
SolarWinds Observability Self-Hosted是美国SolarWinds公司的一款观察平台。 SolarWinds Observability Self-Hosted存在代码问题漏洞,该漏洞源于不可信数据反序列化,可能导致本地权限提升。
CVSS Information
N/A
Vulnerability Type
N/A