漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI start_response() without adding anti-framing protections such as X-Frame-Options or a Content-Security-Policy frame-ancestors restriction.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ajenti Project Ajenti 安全漏洞
Vulnerability Description
ajenti是ajenti团队开源的一个 Linux 和 BSD 模块化服务器管理面板。 Ajenti Project Ajenti 2.2.13及之前版本存在安全漏洞,该漏洞源于HTTP响应初始化空标头列表时缺少反框架保护(如X-Frame-Options或Content-Security-Policy frame-ancestors限制),导致浏览器登录和管理界面存在点击劫持弱点。
CVSS Information
N/A
Vulnerability Type
N/A