Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture
Vulnerability Description
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies, browser storage, HTTP credentials, proxy configuration, user-agent settings, geolocation information, and captured request data. In a multi-user or concurrent deployment, information supplied during one capture could therefore persist and be reused by a subsequent or parallel capture. This could result in the disclosure of authentication cookies, credentials, browser storage, or captured request data belonging to another user. It could also cause requests to be performed with another capture's authentication context, headers, or proxy configuration, potentially enabling unauthorized access to remote resources or interference with other capture operations. The vulnerability is resolved by initializing all capture-specific settings and request data as instance variables in the Capture constructor, ensuring that state is isolated between capture operations.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
Lookyloo PlaywrightCapture 会话机制问题漏洞
Vulnerability Description
Lookyloo PlaywrightCapture是Lookyloo的网页截图捕获工具。 Lookyloo PlaywrightCapture v1.40.2及之前版本存在会话机制问题漏洞,该漏洞源于将捕获特定配置和运行时数据存储为可变的类级变量而非实例级变量,导致在同一个Python进程中运行的多个Capture对象可能共享状态,包括HTTP标头、cookie、浏览器存储、HTTP凭据、代理配置、用户代理设置、地理位置信息和捕获的请求数据,在多用户或并发部署中可能导致身份验证cookie、凭据、浏览器
CVSS Information
N/A
Vulnerability Type
N/A