laptop and a wrench

漏洞

Tokens generated with Portal for ArcGIS and the referrer URL are valid for requests where the referrer is omitted in the Header request.

上次发布: February 23, 2023 Portal for ArcGIS
漏洞 ID 编号 BUG-000154453
已提交December 14, 2022
上次修改时间October 4, 2024
适用范围Portal for ArcGIS
找到的版本10.9.1
操作系统Windows OS
操作系统版本10.0 64 Bit
状态As Designed

附加信息

This is the expected behavior of the software. There are situations where applications need to open pages where the browser does not send a referrer, and in those situations, users expect tokens to work.

重现步骤

漏洞 ID: BUG-000154453

软件:

  • Portal for ArcGIS

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项