Homarr jest otwartym pulpitem nawigacyjnym. Przed wersją 1.54.0 endpoint integration.all tRPC w Homarr był narażony jako publicProcedure, umożliwiając nieuwierzytelnionym użytkownikom pobranie pełnej listy skonfigurowanych integracji. Te metadane zawierają wrażliwe informacje takie jak wewnętrzne adresy URL usług, nazwy integracji i typy serwisów. Problem został naprawiony w wersji 1.54.0.
▸ Pokaż oryginał (EN)
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NHomarr
APPHomarr< 1.54.0
Powiązane podatności
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compro...
Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has ...
Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed p...
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the exe...
Homarr to otwartoźródłowy dashboard. Przed wersją 1.57.0 endpoint rejestracji użytkownika (/api/trpc/user.regi...