Chainguard Academy(edu)在 commit 93dc0e50739c225f5aee2e803800a47fc0feb906 之前的代码(自 commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 起引入)的 nginx.conf 文件中,在后斜杠目录重定向逻辑中使用了面向后端的 变量。该漏洞允许网络路径上的攻击者读取或篡改通过 HTTPS 请求发送给受害者的文档内容,具体当受害者请求一个不带尾随斜杠的目录路径时。由于 TLS 在 Nginx 前面的负载均
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Chainguard | Chainguard Academy (edu) | 0b75ff98057f69b044a3e7194e428066ac5ad0d4 ~ 93dc0e50739c225f5aee2e803800a47fc0feb906 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet