漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Chartbrew: Unauthenticated Chart Filter Endpoint: POST /project/:project_id/chart/:chart_id/filter missing verifyToken + checkPermissions
Vulnerability Description
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POST /project/:project_id/chart/:chart_id/filter is missing both verifyToken and checkPermissions middleware, allowing unauthenticated users to access chart data from any team/project. This issue has been patched in version 4.8.4.
CVSS Information
N/A
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
chartbrew 访问控制错误漏洞
Vulnerability Description
chartbrew是Chartbrew开源的一个数据可视化与仪表盘构建工具。 Chartbrew 4.8.4之前版本存在访问控制错误漏洞,该漏洞源于chart filter端点缺少中间件,可能导致未经验证的用户访问任何团队或项目的图表数据。
CVSS Information
N/A
Vulnerability Type
N/A