OSV 1.4.0 · unreviewed · 修改于 2026-08-25 20:31
发布时间
2026-08-25 20:31
GitHub 审查时间
—
NVD 发布时间
2026-08-25 20:16
源文件
advisories/unreviewed/2026/08/GHSA-7j6f-2mq2-g5vq/GHSA-7j6f-2mq2-g5vq.json
Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated user to access system logs. Attackers with valid user sessions can query GET /api/system/logs and subscribe to SSE and WebSocket log streams to retrieve sensitive operational data including file paths, stack traces, and internal URLs.
该公告没有提供结构化的受影响软件包信息。