漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
better-auth before 1.4.2 basePath Modification DoS
Vulnerability Description
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
better-auth 资源管理错误漏洞
Vulnerability Description
better-auth是better-auth团队开源的一个身份验证框架。 better-auth 1.4.2之前版本存在资源管理错误漏洞,该漏洞源于外部请求可配置baseURL(当未定义时),攻击者可在服务器启动后发起首个请求,污染路由器的基础路径,导致所有路由返回404,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A