Описание
In version 0.6.0 of eosphoros-ai/db-gpt, the uvicorn app created by dbgpt_server uses an overly permissive instance of CORSMiddleware which sets the Access-Control-Allow-Origin to * for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network.
Ссылки
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dbgpt:db-gpt:0.6.0:*:*:*:*:*:*:*
EPSS
Процентиль: 11%
0.00039
Низкий
7.1 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-352
Связанные уязвимости
EPSS
Процентиль: 11%
0.00039
Низкий
7.1 High
CVSS3
8.1 High
CVSS3
Дефекты
CWE-352