Recurly Client Ruby Library是美国Recurly公司的一款用于Recurly的Ruby API封装器。 Recurly Client Ruby Library中的Resource#find方法存在服务器端请求伪造漏洞。攻击者可利用该漏洞控制API密钥或其他重要资源。以下版本受到影响:Recurly Client Ruby Library 2.0.13之前的版本,2.1.11之前的版本,2.2.5之前的版本,2.3.10之前的版本,2.4.11之前的版本,2.5.4之前的版本,2.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Recurly | recurly ruby gem | Versions before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-0906 | Recurly Client Python Library 安全漏洞 | |
| CVE-2017-0907 | Recurly Client .NET Library 安全漏洞 |
No comments yet