漏洞描述: 库中的 存在不受控制的递归漏洞。未认证的远程攻击者可通过构造深层嵌套的 JSON 文档,导致 JSON 解码过程崩溃。任何使用 、 或 对攻击者提供的 JSON 进行解码,且该 JSON 映射到包含自引用或循环消息类型的 Protobuf 模式的 Elixir 应用,均受此漏洞影响。 技术细节: 在 文件中, 函数的 子句在处理每个嵌套层级时,会无条件地递归调用 ,而未递增或未检查解码器的深度计数器。尽管存在 深度保护机制,但该保护仅适用于 和 类型,对自定义消息类型无效。因此, 配置选项对用户自定义消
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-protobuf | protobuf | 0.8.0 ~ 0.17.1 |
cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*
|
|
| elixir-protobuf | protobuf | b0a1d4eaffaf50012fa71a8e931a47cf252d0370 ~ e9432ad1c4099511905353cebcececa3a1f7c3ff |
cpe:2.3:a:elixir-protobuf:protobuf:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet