Perl 版的 Punk 框架在 0.48 至 0.55 版本(不含 0.55)中存在安全漏洞。该漏洞涉及对 Extended CONNECT 请求的路由处理:在 函数中,Extended CONNECT 请求会被错误地路由到任何 GET 路由,且在此过程中未进行 Origin(源站)检查。 在 HTTP/2 和 HTTP/3 协议中,WebSocket 握手请求会以 Extended CONNECT 的形式到达。由于该请求被匹配为 GET 请求,因此它会被转发至所有 GET 路由、API 操作以及挂载点(moun
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0.48 ~ 0.55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet