漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Aqara IAM/SSO Gateway cross-origin resource sharing
Vulnerability Description
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Vulnerability Type
过度许可的跨域白名单
Vulnerability Title
Aqara IAM/SSO Gateway 配置错误漏洞
Vulnerability Description
Aqara IAM/SSO Gateway是美国Aqara公司的一个身份认证与访问管理网关。 Aqara IAM/SSO Gateway存在配置错误漏洞,该漏洞源于跨域资源共享策略问题,可能导致出现未经认证的跨域请求。
CVSS Information
N/A
Vulnerability Type
N/A