TGViewer
WePC_八卦台 WePC_八卦台 @wepc_au · 3.02K subscribers
Post #329 4.15K
哪吒监控曝严重未授权路径穿越漏洞,一条 GET 请求拿下管理员

哪吒监控(nezha)v2.0.13 以下版本存在一个 CVSS 9.1 的严重漏洞(CVE-2026-53519):dashboard 的 NoRoute 处理器用 strings.HasPrefix 做前缀匹配,攻击者构造 /dashboard../data/config.yaml 即可绕过鉴权读取配置文件,其中明文存储着 HS256 签名用的 jwt_secret_key,拿到密钥后伪造任意用户的 JWT cookie,整个 dashboard 直接沦陷——全程无需登录,两个 HTTP 请求搞定。目前官方已在 v2.0.13 修复,建议立即升级。

来源:Github
More from @wepc_au
  1. Sep 22, 2026WePC通告: 台湾恢复!
  2. Sep 22, 2026WePC通告: 有T1路由泄漏导致台湾(有可能扩散到全球)链接爆炸,这个只能等,理论上不会很久。 Jason 2026.09.22 18:50
  3. Sep 15, 2026WePC上新通告: 新西兰家宽(检测结果参考ping0及 pingip.cn ) 产品上线,观摩地址: https://wepc.au/index.php/store/tiktok…
  4. Sep 3, 2026Cogent疑似恢复正常: 2026.09.03 20:15
  5. Sep 3, 20261. Customers located in the Los Angeles and Honolulu areas may be experiencing high latenc…
  6. Sep 2, 2026观察到北美 ISP Cogent 再次出现大面积网络中断丢包现象,已反馈至运营商,暂无进展。 2026.09.02 22:00
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →