Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • J JxaInterfaceChecking
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1
    • Issues 1
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 0
    • Merge requests 0
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Infrastructure Registry
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • 段丁博
  • JxaInterfaceChecking
  • Issues
  • #1

Closed
Open
Created Jul 10, 2020 by 段丁博@duandingboMaintainer

安全漏洞提醒

Created by: code6er

漏洞类型:邮箱 SMTP 信息泄露

漏洞等级:高

漏洞地址:https://github.com/JinghangAI/JxaInterfaceChecking/blob/337ec55de4445d7059c3968e258290a2091250af/config/mail_config.txt

漏洞危害:任何人可以通过 SMTP 账号密码收发邮件,进而通过邮箱重置其他平台密码

解决方案:重置 SMTP 密码并检查邮箱是否有敏感信息泄露(请勿只修改代码,历史版本库依旧可见)

本次扫描结果由 [ 码小六 ] https://github.com/4x99/code6 提供(欢迎 star)

Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking