The api /api/snapshot and /api/get_log_file would allow...
High severity
Unreviewed
Published
Dec 22, 2023
to the GitHub Advisory Database
•
Updated Dec 22, 2023
Description
Published by the National Vulnerability Database
Dec 18, 2023
Published to the GitHub Advisory Database
Dec 22, 2023
Last updated
Dec 22, 2023
The api /api/snapshot and /api/get_log_file would allow unauthenticated access.
It could allow a DoS attack or get arbitrary files from FE node.
Please upgrade to 2.0.3 to fix these issues.
References