Количество 2
Количество 2
CVE-2026-67439
OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs permission, allowing a user with exec permission but logs:false to read action output. This issue is fixed in version 3000.17.0.
GHSA-jm28-2wcr-qf3h
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67439 OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs permission, allowing a user with exec permission but logs:false to read action output. This issue is fixed in version 3000.17.0. | CVSS3: 4.3 | 0% Низкий | 9 дней назад | |
GHSA-jm28-2wcr-qf3h OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output | CVSS3: 4.3 | 0% Низкий | 8 дней назад |
Уязвимостей на страницу