laptop and a wrench

漏洞

By default, anonymous users can upload files to the "/server/rest/services/Hosted/<FeatureService>/FeatureServer/uploads/upload" API when the feature service is shared publicly.

ArcGIS GIS Server
漏洞 ID 编号 BUG-000175606
已提交April 4, 2025
上次修改时间July 21, 2025
适用范围ArcGIS GIS Server
找到的版本11.4
操作系统Windows Server
操作系统版本2022
状态In Review

解决办法

image.png

In order to disable anonymous users from uploading files to a publicly shared feature service, the capability must be removed in the "/server/admin/services/Hosted/<Feature Service Name>.FeatureServer/edit" JSON.

By Default these are the allowed capabilities: ""capabilities": "Query,Create,Update,Delete,Editing,Uploads","

重现步骤

漏洞 ID: BUG-000175606

软件:

  • ArcGIS GIS Server

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项