脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Mist Community Edition API Token views.py create_token access control
脆弱性説明
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.2 is able to address this issue. The identifier of the patch is db10ecb62ac832c1ed4924556d167efb9bc07fad. It is recommended to upgrade the affected component.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
脆弱性タイプ
访问控制不恰当
脆弱性タイトル
Mist 安全漏洞
脆弱性説明
Mist是美国Mist公司的一个开源的多云管理平台。 Mist存在安全漏洞,该漏洞源于文件src/mist/api/auth/views.py中函数create_token存在访问控制不当。
CVSS情報
N/A
脆弱性タイプ
N/A