Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nuclei: Local File Read via require() Module Loader Bypass
Vulnerability Description
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This issue has been patched in version 3.8.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
Nuclei 访问控制错误漏洞
Vulnerability Description
Nuclei是ProjectDiscovery开源的一个基于简单 YAML 的 DSL 的快速可定制漏洞扫描器。 Nuclei 3.0.0版本至3.8.0之前版本存在访问控制错误漏洞,该漏洞源于JavaScript协议运行时允许通过require()函数读取本地.js和.json文件,绕过默认本地文件访问限制。
CVSS Information
N/A
Vulnerability Type
N/A