CVE-2026-92760
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 6.5
- EPSS
- —
- CWE
- CWE-863
- KEV Durumu
- Hayır
Shlink 5.1.6 sürümüne kadar, Mercure abonelik tokenleri verirken API anahtarı rol kısıtlamalarını zorlamaktan başarısız oluyor. Bu, kısıtlı anahtarların tüm konulara abone olmasını sağlıyor. Yalnızca yazar veya domaine özgü anahtarlara sahip saldırganlar, mercure-info endpointüne erişerek, yetki sınırının dışında olan URL'ler için referrer, kullanıcı aracı, coğrafi konum ve kısa URL nesneleri dahil ziyaret verilerini alabilir.
Orijinal açıklama (İngilizce)
Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info endpoint to receive visit data including referrer, user agent, geolocation, and full short URL objects for URLs outside their authorization boundary.
Referanslar
- https://github.com/shlinkio/shlink
- https://github.com/shlinkio/shlink-common/blob/main/src/Mercure/LcobucciJwtProvider.php#L38-L41
- https://github.com/shlinkio/shlink/blob/v5.1.6/module/Rest/src/Action/MercureInfoAction.php#L26-L42
- https://github.com/shlinkio/shlink/issues/2633
- https://www.vulncheck.com/advisories/shlink-through-5.1.6-mercure-token-authorization-bypass
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
