Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

【安全漏洞】可抓取关键会话包进行会话重放,系统未限制会话重放 #940

Open
neronkl opened this issue Mar 7, 2023 · 2 comments
Assignees
Labels
canway 需求来源为嘉为侧

Comments

@neronkl
Copy link
Contributor

neronkl commented Mar 7, 2023

用文字描述你遇到的问题

可抓取文件导入包进行会话重放,系统未限制会话重放

重现方法

  1. 使用Burp Suite抓取文件导入包并多次对文件导入包进行回放

image

预期行为

重放成功

版本

  • 提供用户管理的具体版本号
    2.0.8(V2.5.1 也存在该问题)
  • 是否是企业版问题?

如果是 SaaS 页面问题,请提供使用的操作系统和浏览器信息

  • OS: [e.g. iOS]
  • Browser [e.g. chrome, safari]
  • Version [e.g. 22]

额外信息

任何你觉得有助于问题解决的内容

@wklken
Copy link
Collaborator

wklken commented Mar 9, 2023

调研下防止会话重放的方案? 不要自己搞

@Canway-shiisa Canway-shiisa added this to the Y2023M11 milestone Mar 13, 2023
@nannan00 nannan00 modified the milestones: Y2023M11, Y2023M13 Mar 27, 2023
@nannan00
Copy link
Collaborator

暂时挂起,如果有紧急需要再推动

@nannan00 nannan00 removed this from the Y2023M13 milestone Mar 27, 2023
@Canway-shiisa Canway-shiisa added the canway 需求来源为嘉为侧 label Mar 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
canway 需求来源为嘉为侧
Projects
None yet
Development

No branches or pull requests

4 participants