漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
will-moss Isaiah Master Websocket server.go Server.Handle authorization
Vulnerability Description
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
will-moss isaiah 授权问题漏洞
Vulnerability Description
will-moss isaiah是will-moss个人开发者的一款Web中间件软件。 will-moss isaiah 1.36.9及之前版本存在授权问题漏洞,该漏洞源于Master Websocket Handler组件中文件app/server/server/server.go的Server.Handle函数对参数Agent操作导致缺少授权,可能允许远程攻击。以下版本受到影响:1.36.0版本、1.36.1版本、1.36.2版本、1.36.3版本、1.36.4版本、1.36.5版本、1.36.6版本
CVSS Information
N/A
Vulnerability Type
N/A