漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Zerobyte has Authentication Bypass by Primary Weakness
Vulnerability Description
Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This is dangerous for those who have exposed Zerobyte to be used outside of their internal network. A fix has been applied in both version 0.19.0 and 0.18.5. If immediate upgrade is not possible, restrict network access to the Zerobyte instance to trusted networks only using firewall rules or network segmentation. This is only a temporary mitigation; upgrading is strongly recommended.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
使用基本弱点进行的认证绕过
Vulnerability Title
Zerobyte 安全漏洞
Vulnerability Description
Zerobyte是Nico个人开发者的一个主机自动备份软件。 Zerobyte 0.18.5之前版本和0.19.0之前版本存在安全漏洞,该漏洞源于身份验证中间件未正确应用于API端点,可能导致身份验证绕过。
CVSS Information
N/A
Vulnerability Type
N/A