Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Summarize Insecure Daemon Configuration File Permissions
Vulnerability Description
Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. A local attacker can exploit these permissive permissions to read the daemon bearer token and persisted provider credentials, enabling unauthorized access to the daemon or recovery of sensitive API keys.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Summarize 安全漏洞
Vulnerability Description
Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.14.1及之前版本存在安全漏洞,该漏洞源于守护进程配置目录和文件使用默认文件系统权限,在类Unix系统上可能被世界可读,导致本地攻击者读取存储在~/.summarize/daemon.json中的承载令牌和API凭据。本地攻击者可利用这些宽松权限读取守护进程承载令牌和持久化提供者凭据,从而未授权访问守护进程或恢复敏感API密钥。
CVSS Information
N/A
Vulnerability Type
N/A