深信服运维安全管理系统 /fort;login/app/get_all_application_release 未授权访问漏洞

Description

深信服运维安全管理系统的/fort;login/app/get_all_application_release接口存在敏感信息泄露漏洞。攻击者可通过发送恶意的GET请求,无需授权即可访问该接口,获取包括跳板机IP、管理员账号、密码哈希、远程桌面端口等在内的核心敏感信息,对目标系统的内网安全造成严重威胁。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities