Skip to content

Latest commit

 

History

History
22 lines (13 loc) · 749 Bytes

radar Authentication bypass vulnerability.md

File metadata and controls

22 lines (13 loc) · 749 Bytes
Vulnerability description:

Radar is an open-source lightweight real-time risk control engine.Radar has an authentication bypass vulnerability, and any interface can be accessed without authentication.

https://github.com/wfh45678/radar

Version:

<= V1.0.8

Vulnerability Recurrence:

Choose any interface that requires authentication to access, example:/services/v1/model/list

Access failed without authentication Image

Add/aa/../ Successfully bypassed authentication access Image

Vulnerability Analysis: