go-micro 在 6.0.0 版本之前存在不正确的证书验证漏洞,该漏洞允许网络攻击者冒充服务,因为共享的 TLS 辅助模块默认将 设置为 true。中间人攻击者可以提供任意证书以拦截或修改 gRPC 传输、HTTP、RabbitMQ 消息队列代理以及 Consul 或 etcd 注册表中的通信流量,其中包括身份验证令牌和凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet