6.1.0 版本之前的 gist RubyGem 存在证书验证不当的安全漏洞,允许网络路径上的攻击者拦截 HTTPS 流量。由于 lib/gist.rb 中的 http_connection 设置了 VERIFY_NONE(不验证证书),攻击者可以提供任意证书以读取或篡改 GitHub API 流量,从而窃取 OAuth 令牌和登录凭据,进而读取和修改受害者的 gist 内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet