漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Anchore Enterprise Privilege Escalation via User Management API
Vulnerability Description
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权API的不正确使用
Vulnerability Title
Anchore Enterprise 权限许可和访问控制问题漏洞
Vulnerability Description
Anchore Enterprise是Anchore公司的一款容器镜像安全分析与合规管理的平台。 Anchore Enterprise 5.11.0版本至5.27.1版本和6.0.0版本存在权限许可和访问控制问题漏洞,该漏洞源于用户管理API存在不当的权限提升问题,可能导致经过身份验证的攻击者通过API调用修改用户权限,从而获取额外资源和操作的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A