漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header
Vulnerability Description
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only for a key identifier). Because JWT headers are Base64-encoded rather than encrypted, the private key could be recovered by anything that logged or inspected the JWT. An attacker who obtained the key could impersonate the service account and access or modify any Google Cloud resource it was authorized to use. Only instances using Google Service Account credentials are affected.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L
Vulnerability Type
敏感数据的明文存储
Vulnerability Title
n8n 加密问题漏洞
Vulnerability Description
n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 1.123.64之前版本、2.29.8版本和2.30.1版本存在加密问题漏洞,该漏洞源于配置Google Service Account密钥时,完整的PEM私钥被错误放入JWT头的kid字段,且JWT头仅进行Base64编码,导致私钥可能被记录或检查JWT的任何对象恢复,攻击者获得密钥后可模拟服务账户访问或修改Google Cloud资源。
CVSS Information
N/A
Vulnerability Type
N/A