Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Server-side Request Forgery (SSRF)
Vulnerability Description
The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Link Preview JS 代码问题漏洞
Vulnerability Description
Link Preview JS是用于提取网络链接信息的工具。 Link Preview JS 2.1.16之前版本存在安全漏洞,该漏洞源于有缺陷的 DNS 重新绑定保护。
CVSS Information
N/A
Vulnerability Type
N/A