In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
高危 CVSS 7.4
摘要
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/muety/wakapi/commit/ce91eac2c2d9b29a00873554d2ecef76f10b9087
- https://github.com/muety/wakapi/releases/tag/2.17.6
- https://github.com/muety/wakapi/security/advisories/GHSA-x48w-3rq3-w2pq
时间线
- nvd_ingest NVD