脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
脆弱性説明
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
脆弱性タイプ
授权机制不正确
脆弱性タイトル
Google MCP Toolbox for Databases 授权问题漏洞
脆弱性説明
Google MCP Toolbox for Databases是美国Google公司的数据库管理工具。 Google MCP Toolbox for Databases v1.3.0版本和v1.4.0版本存在授权问题漏洞,该漏洞源于直接HTTP API工具调用端点存在授权不正确问题,可能导致未经身份验证的攻击者在--enable-api标志激活时通过遗留HTTP端点发送工具调用请求来调用受scopeRequired功能保护的工具。
CVSS情報
N/A
脆弱性タイプ
N/A