Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
dataCycle Public DataLink Text File Download Ignores Validity And Authorization
Vulnerability Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached text file directly, even if the link is expired, the caller is unauthenticated, or the normal show flow would have denied access. Because the route is public and the mailer embeds the direct file URL, any leaked, forwarded, logged, or stale email link can continue to expose the attachment.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
dataCycle CORE 授权问题漏洞
Vulnerability Description
dataCycle dataCycle CORE是奥地利dataCycle组织的一个数据管理系统的核心处理与框架模块。 dataCycle CORE 25.07.3及之前版本存在授权问题漏洞,该漏洞源于授权问题,可能导致具有DataLink UUID的攻击者直接获取附加文本文件,即使链接过期、调用者未经验证或正常访问流程拒绝访问,任何泄露、转发、记录或过时的电子邮件链接仍能暴露附件。
CVSS Information
N/A
Vulnerability Type
N/A