Coinworld News: The 360 Security Cloud team received an official email from OpenClaw founder Peter. In his reply, Peter formally confirmed the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability exclusively discovered by the 360 team. Currently, 360 has synced this critical vulnerability to the National Information Security Vulnerability Sharing Platform (CNVD), assisting the entire network in cutting off the risk source at the earliest opportunity. The confirmed WebSocket unauthenticated upgrade vulnerability is a zero-day (0Day) vulnerability. Attackers can exploit this vulnerability to silently bypass permission authentication through WebSocket, obtain control of the intelligent agent gateway, and potentially cause target system resource exhaustion or complete collapse.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin