漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings
Vulnerability Description
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an arbitrary password hash, obtain a valid session cookie, and lock out the legitimate operator from their own instance.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Hermes Web UI 访问控制错误漏洞
Vulnerability Description
Hermes Web UI是Nathan Esquenazi个人开发者的一个轻量级、暗色主题的自主智能体Web界面。 Hermes Web UI 0.51.358之前版本存在访问控制错误漏洞,该漏洞源于访问控制不当,可能导致未经身份验证的远程攻击者通过向设置API端点提交_set_password参数劫持初始设置。攻击者可在首次运行设置窗口期间发送POST请求,持久化任意密码哈希,获取有效会话cookie,并锁定合法操作员。
CVSS Information
N/A
Vulnerability Type
N/A