漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
在安全决策中依赖未经信任的输入
Vulnerability Title
Sinatra 安全漏洞
Vulnerability Description
Sinatra是Sinatra开源的一个DSL,用于以最少的努力快速创建Ruby中的web应用程序 Sinatra存在安全漏洞。攻击者利用该漏洞可以通过在标头中插入任意地址来触发开放重定向攻击。
CVSS Information
N/A
Vulnerability Type
N/A