Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance API
Vulnerability Description
yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the @PreAuthorize annotation. Attackers can query any process-instance identifier through the unguarded GET endpoint to read sensitive workflow data including submitted form variables, approver identities, approval and rejection comments, and process BPMN XML without ownership or tenant party verification.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
YunaiV yudao-cloud 授权问题漏洞
Vulnerability Description
YunaiV yudao-cloud是YunaiV个人开发者开源的一个后台管理系统。 yudao-cloud 2026.06之前版本存在授权问题漏洞,该漏洞源于BPM模块中存在访问控制失效,允许通过将攻击者控制的过程实例标识符提交到缺少@PreAuthorize注解的未保护端点,使任何经过身份验证的用户访问任意流程实例记录。攻击者可通过未受保护的GET端点查询任意流程实例ID,读取敏感工作流数据,包括已提交的表单变量、审批者身份、批准和拒绝意见以及流程BPMN XML,而无需验证所有权或租户身份。
CVSS Information
N/A
Vulnerability Type
N/A