漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MaxKB: Broken Access Control in MaxKB OSS URL Fetch API
Vulnerability Description
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL path without validating ownership, allowing attackers to perform operations under other applications’ policies. This vulnerability is fixed in 2.8.1.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
MaxKB 安全漏洞
Vulnerability Description
MaxKB是1Panel-dev开源的一款基于大语言模型和 RAG 的开源知识库问答系统。 MaxKB 2.8.0及之前版本存在安全漏洞,该漏洞源于OSS文件服务URL获取API中存在访问控制缺陷,可能导致攻击者在其他应用策略下执行操作。
CVSS Information
N/A
Vulnerability Type
N/A