目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-59349— Dragonfly 安全漏洞

AI Predicted 5.9 Difficulty: Moderate EPSS 0.11% · P1

Possible ATT&CK Techniques 1AI

T1564.004 · NTFS File Attributes
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-59349の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Directories created via os.MkdirAll are not checked for permissions
ソース: CVE Program / CVE List V5
脆弱性説明
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses the os.MkdirAll function to create certain directory paths with specific access permissions. This function does not perform any permission checks when a given directory path already exists. This allows a local attacker to create a directory to be used later by DragonFly2 with broad permissions before DragonFly2 does so, potentially allowing the attacker to tamper with the files. This vulnerability is fixed in 2.1.0.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
ソース: CVE Program / CVE List V5
脆弱性タイプ
关键资源的不正确权限授予
ソース: CVE Program / CVE List V5
脆弱性タイトル
Dragonfly 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Dragonfly是DragonflyDB开源的一个框架,可以对任何内容类型进行动态处理。 Dragonfly 2.1.0之前版本存在安全漏洞,该漏洞源于os.MkdirAll函数未对现有目录路径执行权限检查,可能导致本地攻击者篡改文件。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
dragonflyossdragonfly < 2.1.0 -

II. CVE-2025-59349の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-59349のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · dragonflyoss · 2025-09-17 · 11 CVEs total

CVE-2025-59350Timing attacks against Proxy’s basic authentication are possible
CVE-2025-59352Dragonfly allows arbitrary file read and write on a peer machine
CVE-2025-59345Dragonfly did not enable authentication for some Manager’s endpoints
CVE-2025-59348Dragonfly incorrectly handles a task structure’s usedTraffic field
CVE-2025-59347Dragonfly Manager makes requests to external endpoints with disabled TLS authentication
CVE-2025-59351Dragonfly possibly panics due to nil pointer dereference when using variables created alon
CVE-2025-59346Dragonfly server-side request forgery vulnerability
CVE-2025-59410Dragonfly tiny file download uses hard coded HTTP protocol
CVE-2025-59354Dragonfly has weak integrity checks for downloaded files
CVE-2025-59353Manager generates mTLS certificates for arbitrary IP addresses

IV. 関連脆弱性

V. CVE-2025-59349へのコメント

まだコメントはありません


コメントを残す