Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
Vulnerability Description
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
CyberArk Idira Secrets Manager SaaS Edge 访问控制错误漏洞
Vulnerability Description
CyberArk Idira Secrets Manager SaaS Edge是美国CyberArk公司的一个分布式机密访问节点组件。 CyberArk Idira Secrets Manager SaaS Edge 1.8之前版本存在访问控制错误漏洞,该漏洞源于内部身份验证组件中访问控制不当,可能导致远程未经身份验证的攻击者通过提交特制请求,在特定情况下操纵内部验证机制,绕过身份验证并获取访问令牌。
CVSS Information
N/A
Vulnerability Type
N/A