漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NousResearch hermes-agent Webhooks Endpoint webhook.py missing authentication
Vulnerability Description
A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitation is known to be difficult. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Hermes Agent 授权问题漏洞
Vulnerability Description
Hermes Agent是Nous Research开源的一款具备自我学习循环的AI代理工具。 Hermes Agent 0.8.0版本存在授权问题漏洞,该漏洞源于Webhooks Endpoint组件gateway/platforms/webhook.py文件中未知功能对参数_INSECURE_NO_AUTH的操作导致缺少身份验证,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A