漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie
Vulnerability Description
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path construction within the authglinet middleware. Attackers can craft a request with a traversal payload in the Admin-Token header to redirect file reads to arbitrary paths.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
AdGuardHome 路径遍历漏洞
Vulnerability Description
AdGuardHome是AdguardTeam的阻止 DNS 服务器的全网广告和跟踪器。 AdGuardHome存在路径遍历漏洞,该漏洞源于认证绕过,可能导致未经身份验证的攻击者通过在Admin-Token cookie中提供路径遍历序列获得完全管理员访问权限。
CVSS Information
N/A
Vulnerability Type
N/A