漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events
Vulnerability Description
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Summarize 代码问题漏洞
Vulnerability Description
Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.15.1之前版本存在代码问题漏洞,该漏洞源于悬停摘要功能中的问题,可能导致恶意页面在攻击者控制的链接上分配合成鼠标悬停事件,导致扩展使用存储的令牌进行认证守护进程请求而不验证事件可信度。攻击者可以将本地或私有网络URL放置在可悬停链接后面,通过守护进程路由认证请求,可能访问敏感内部端点。
CVSS Information
N/A
Vulnerability Type
N/A