CVE-2026-92800
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 6.8
- EPSS
- —
- CWE
- CWE-613
- KEV Durumu
- Hayır
5.4.1 sürümünden önceki Docs, üst belgelerde erişimin iptal edilmesini, websocket işbirliği bağlantılarının uygun şekilde iptal etmemektedir. Erişimi iptal edilen saldırganlar, hiçbir zaman kesintiye uğramayan açık websocket oturumları aracılığıyla alt belgelerde gerçek zamanlı okuma ve yazma erişimi elde tutabilirler.
Orijinal açıklama (İngilizce)
Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.
Referanslar
- https://github.com/geo-chen/oss/blob/main/docs.md
- https://github.com/suitenumerique/docs
- https://github.com/suitenumerique/docs/blob/v5.3.0/src/backend/core/api/viewsets.py#L2825-L2860
- https://github.com/suitenumerique/docs/commit/d35b81a6ed526dc284c8d0f68b762f2e81ffab13
- https://www.vulncheck.com/advisories/docs-before-5.4.1-stale-collaboration-session-after-access-revocation
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
