Dragonfly是DragonflyDB开源的一个框架,可以对任何内容类型进行动态处理。 Dragonfly 2.1.0之前版本存在安全漏洞,该漏洞源于gRPC API和HTTP API允许对等节点发送请求强制接收节点在任意文件系统位置创建文件和读取任意文件,可能导致窃取其他对等节点的秘密数据和在目标机器上执行远程代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dragonflyoss | dragonfly | < 2.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59350 | Timing attacks against Proxy’s basic authentication are possible | |
| CVE-2025-59345 | Dragonfly did not enable authentication for some Manager’s endpoints | |
| CVE-2025-59348 | Dragonfly incorrectly handles a task structure’s usedTraffic field | |
| CVE-2025-59347 | Dragonfly Manager makes requests to external endpoints with disabled TLS authentication | |
| CVE-2025-59351 | Dragonfly possibly panics due to nil pointer dereference when using variables created alon | |
| CVE-2025-59346 | Dragonfly server-side request forgery vulnerability | |
| CVE-2025-59349 | Directories created via os.MkdirAll are not checked for permissions | |
| CVE-2025-59410 | Dragonfly tiny file download uses hard coded HTTP protocol | |
| CVE-2025-59354 | Dragonfly has weak integrity checks for downloaded files | |
| CVE-2025-59353 | Manager generates mTLS certificates for arbitrary IP addresses |
No comments yet