Описание
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.7 (исключая)
cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00417
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 6.5
github
около 1 месяца назад
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.
EPSS
Процентиль: 34%
0.00417
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-306