漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding Validation
Vulnerability Description
A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue was fixed by disallowing stray data after a chunk, and is no longer exploitable. No action is required as Classic Application Load Balancer service after 2025-04-26 is not vulnerable.
CVSS Information
N/A
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Vulnerability Title
Google Cloud Classic Application Load Balancer 安全漏洞
Vulnerability Description
Google Cloud Classic Application Load Balancer是美国谷歌(Google)公司的一个传统应用负载均衡服务,用于在云环境中自动分配流量到后端服务实例。 Google Cloud Classic Application Load Balancer存在安全漏洞,该漏洞源于对分块编码HTTP请求处理不当,可能导致请求走私攻击。
CVSS Information
N/A
Vulnerability Type
N/A