漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
Vulnerability Description
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow and code files belonging to other tenants on the same worker, exposing embedded data and allowing modified code to execute on a victim tenant's next flow run. This issue is fixed in version 0.84.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
信息暴露
Vulnerability Title
activepieces 信息泄露漏洞
Vulnerability Description
activepieces activepieces是activepieces的一个自动化工作流平台。 activepieces 0.84.0之前版本存在安全漏洞,该漏洞源于Code piece沙箱中的未清理路径段,可能导致认证的流作者访问其他租户的缓存流和代码文件,暴露嵌入数据并允许修改代码在受害者租户的下一次流运行时执行。
CVSS Information
N/A
Vulnerability Type
N/A