OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest sign…
高危 CVSS 7.5
摘要
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/OpenSignLabs/OpenSign
- https://github.com/OpenSignLabs/OpenSign/blob/v2.41.0/apps/OpenSignServer/cloud/parsefunction/getDocument.js#L20-L32
- https://github.com/OpenSignLabs/OpenSign/issues/2218
- https://www.vulncheck.com/advisories/opensign-through-2.41.3-information-disclosure-via-getdocument
时间线
- nvd_ingest NVD