漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SiYuan before v3.7.4 Path Traversal via getUniqueFilename
Vulnerability Description
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem layout and installed software.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
SiYuan 授权问题漏洞
Vulnerability Description
SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.4之前版本存在授权问题漏洞,该漏洞源于getUniqueFilename端点存在路径遍历问题,允许匿名读者在未经验证或限制的情况下探测文件系统存在性,攻击者可提供任意绝对路径判断主机上文件和目录是否存在,导致文件系统布局和已安装软件信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A