脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget
脆弱性説明
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is registered with CheckAuth only and performs no authorization checks (no CheckReadonly, no publish-access or encrypted-notebook gating). Given a database identifier taken from a published page and a keyword, an anonymous reader can query the endpoint to retrieve matching database row content, including rows that publish filters (FilterAttributeViewByPublishAccess) would otherwise withhold. No released stable version is affected.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
脆弱性タイプ
授权机制缺失
脆弱性タイトル
SiYuan 授权问题漏洞
脆弱性説明
SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.4之前版本存在授权问题漏洞,该漏洞源于/api/av/getAttributeViewSearchTarget端点缺少授权检查,可能导致匿名读者获取数据库行内容,包括发布过滤器隐藏的内容。
CVSS情報
N/A
脆弱性タイプ
N/A