哪吒(Nezha)监控面板在 1.8.0 至 2.3.13 版本之间存在一个不正确的锁定漏洞,该漏洞会导致在非延迟互斥锁解锁操作于 nil 映射恐慌路径上发生时发生内存泄漏。任何经过身份验证的非管理员成员均可通过发起四次通知 API 调用,永久性地使告警子系统死锁,并通过阻塞请求耗尽系统内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet