【高】未授权访问(31处)

Blade 未结 2 15

一、该问题的重现步骤是什么?

1. 未授权访问漏洞是指系统或应用程序在没有适当的身份验证或授权机制的情况下,允许用户访问受保护的资源。

http://localhost:1888/exhibition/security/attackFrequencyDZJ/scoutNumber

http://localhost:1888/exhibition/security/attackFrequency/customerAttackList1

http://localhost:1888/exhibition/security/attackFrequencyDZJ/threatAbroadTop6

http://localhost:1888/exhibition/security/attackFrequency/threatAll

http://localhost:1888/exhibition/security/attackFrequency/threatDomestic

http://localhost:1888/exhibition/security/attackFrequency/attackMethod

http://localhost:1888/exhibition/security/attackFrequencyDZJ/threatLevel

http://localhost:1888/exhibition/security/attackFrequencyDZJ/attackEventFlow

http://localhost:1888/exhibition/security/attackFrequency/threatDomesticTop6

http://localhost:1888/exhibition/security/attackFrequencyDZJ/attackSituation

http://localhost:1888/exhibition/security/attackFrequency/customerAttackList2

http://localhost:1888/exhibition/security/attackFrequency/threatLevel

http://localhost:1888/exhibition/security/attackFrequency/threatAbroad

http://localhost:1888/exhibition/security/attackFrequency/threatAbroadTop6

http://localhost:1888/exhibition/security/attackFrequencyDZJ/invasionNumber

http://localhost:1888/exhibition/security/attackFrequencyDZJ/attackMethod

http://localhost:1888/exhibition/security/attackFrequencyDZJ/customerAttackList1

http://localhost:1888/exhibition/security/attackFrequencyDZJ/threatAbroad

http://localhost:1888/exhibition/security/attackFrequency/attackSituation

http://localhost:1888/exhibition/security/attackFrequencyDZJ/threatAll

http://localhost:1888/exhibition/security/attackFrequencyDZJ/customerFlow


二、你期待的结果是什么?实际看到的又是什么?

无法直接访问

三、你正在使用的是什么产品,什么版本?在什么操作系统上?

org.springbladescreen-manage-bootjar4.1.0.RELEASE

四、请提供详细的错误堆栈信息,这很重要。


五、若有更多详细信息,请在下面提供。

2条回答
  • bladex没有这些API,让开发这些API的同事自行处理,看看他是不是自己设置了放行等操作

    0 讨论(0)
  • 22分钟前

    ok,找到了

    0 讨论(0)
提交回复