漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
Vulnerability Description
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulation of the argument Username causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
AstrBot 授权问题漏洞
Vulnerability Description
AstrBot是AstrBot团队开源的一个多平台 LLM 聊天机器人及开发框架。 AstrBot 4.25.5及之前版本存在授权问题漏洞,该漏洞源于文件astrbot/dashboard/routes/open_api.py中session-listing Endpoint组件的OpenApiRoute.get_chat_sessions函数对Username参数操作不当,导致授权绕过。
CVSS Information
N/A
Vulnerability Type
N/A