运行 nextjs-nextjs--CVE-2024-51479-20260318012913

漏洞条目
nextjs--CVE-2024-51479
实证状态
verified-real
复现 Profile
nextjs-authz-bypass
Artifact 模式
local-fixture

Mermaid 时间线

flowchart LR
A["选择 Advisory"] --> B["解析 Repro Profile"]
B --> C["生成 Compose 环境"]
C --> D["采集基线快照"]
D --> E["执行受控攻击步骤"]
E --> F["浏览器回放验证"]
F --> G["收集日志与证据"]
G --> H["回写 Registry 与报告"]

运行时间线

时间步骤状态说明
2026-03-18T01:29:13+00:00select-advisorycompletednextjs--CVE-2024-51479
2026-03-18T01:29:13+00:00resolve-repro-profilecompletednextjs-authz-bypass
2026-03-18T01:29:13+00:00doctorcompletedall checks passed
2026-03-18T01:29:16+00:00provision-compose-environmentready-
2026-03-18T01:29:16+00:00wait-readycompletedbaseline urls ready (1)
2026-03-18T01:29:16+00:00seed-environmentcompletedsteps=1
2026-03-18T01:29:16+00:00baseline-snapshotcompletedurls=1
2026-03-18T01:29:16+00:00controlled-attack-chaincompletedsteps=1
2026-03-18T01:29:16+00:00collect-logs-and-evidencecompletedcontainer_logs=1
2026-03-18T01:29:17+00:00cleanup-compose-environmentcompleteddocker compose down completed
2026-03-18T01:29:17+00:00update-registry-and-reportscompletednextjs-nextjs--CVE-2024-51479-20260318012913

攻击步骤

工具状态输出
nextjs.authz-bypasscompleted/Users/x/websafe/06-case-studies/generated-runs/nextjs-nextjs--CVE-2024-51479-20260318012913/logs/attack.json

证据清单