Encode OSS Uvicorn是英国Encode OSS公司的一款基于uvloop和httptools构建的ASGI(Web服务器网关接口)服务器。 Encode OSS Uvicorn 0.11.7之前版本中存在注入漏洞,该漏洞源于程序没有转义HTTP标头中的CRLF序列。攻击者可利用该漏洞向HTTP相应中添加任意标头或使其返回任意相应主体。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | uvicorn | 0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-7694 | 3.7 LOW | Log Injection |
| CVE-2020-12845 | Cherokee 代码问题漏洞 | |
| CVE-2020-12460 | OpenDMARC 缓冲区错误漏洞 | |
| CVE-2020-12880 | Pulse Secure Pulse Connect Secure和Pulse Policy Secure 信息泄露漏洞 | |
| CVE-2020-15593 | Riverbed Technology SteelCentral Aternity Agent 安全漏洞 | |
| CVE-2020-15592 | Riverbed Technology SteelCentral Aternity Agent 路径遍历漏洞 | |
| CVE-2020-11110 | Grafana 跨站脚本漏洞 | |
| CVE-2020-9251 | Huawei Mate 20 授权问题漏洞 | |
| CVE-2020-9077 | Huawei P30 信息泄露漏洞 | |
| CVE-2020-15953 | LibEtPan 注入漏洞 | |
| CVE-2020-15954 | KDE KMail 安全漏洞 |
No comments yet