漏洞描述
Adobe Experience Manager QueryBuilder endpoint allows unauthenticated attackers to extract sensitive user repository data, including password hashes from the rep:password field in /home/users. This vulnerability bypasses access controls and exposes bcrypt/SHA-256 password hashes through the querybuilder.json API, enabling potential credential compromise and account takeover attacks.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
experienceleague.adobe.comhttps://experienceleague.adobe.com/docs/experience-manager-65/developing/platform/query-builder/querybuilder-api.html↗slcyber.iohttps://slcyber.io/assetnote-security-research-center/finding-critical-bugs-in-adobe-experience-manager/↗github.comhttps://github.com/assetnote/hopgoblin↗