漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
dataCycle Public Markdown Path Traversal Via /docs/*path
Vulnerability Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and static markdown renderer accepts attacker-controlled path segments and only runs them through the Rails HTML sanitizer, which does not remove directory traversal sequences. An unauthenticated attacker can traverse out of the intended `docs` or `static` directories and render arbitrary `.md` files from the application root or engine root. This is patched in version 26.06.08.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
dataCycle CORE 路径遍历漏洞
Vulnerability Description
dataCycle dataCycle CORE是奥地利dataCycle组织的一个数据管理系统的核心处理与框架模块。 dataCycle CORE 25.07.3及之前版本存在路径遍历漏洞,该漏洞源于文档和静态markdown渲染器接受攻击者控制的路径段且仅通过Rails HTML清理器处理,未移除目录遍历序列,可能导致未经身份验证的攻击者遍历出指定的docs或static目录,并渲染应用程序根或引擎根中的任意.md文件。
CVSS Information
N/A
Vulnerability Type
N/A