CVE-2026-92749
YüksekTeknik Veri (Otomatik)
- CVSS Skoru
- 8.1
- EPSS
- —
- CWE
- CWE-338
- KEV Durumu
- Hayır
SafeLine 9.4.1 sürümüne kadar, yönetim konsolu oturum imzalama gizli anahtarı bir zaman-bazlı math/rand jeneratöründen türetilir, bu da saldırganların anahtarı çevrimdışı olarak yeniden oluşturmasına olanak tanır. Kurulum zamanını sınırlayabilen kimliği doğrulanmamış uzaktan saldırganlar, gizli anahtarı yeniden oluşturup geçerli yönetici oturum çerezleri oluşturarak korunan sitelerin kontrolünü ele geçirebilir.
Orijinal açıklama (İngilizce)
SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.
Referanslar
- https://github.com/chaitin/SafeLine
- https://github.com/chaitin/SafeLine/blob/v9.4.1/management/webserver/model/option.go#L27
- https://github.com/chaitin/SafeLine/blob/v9.4.1/management/webserver/utils/random.go#L10-L17
- https://github.com/chaitin/SafeLine/issues/1298
- https://www.vulncheck.com/advisories/safeline-through-9.4.1-authentication-bypass-via-weak-session-secret
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
