漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix check while pointing the OIDC discovery and JWKS fetches at a server the attacker controls. An unauthenticated caller of POST /v1/upload/sbom can use this to force PIA to make outbound HTTP(S) requests to an arbitrary attacker-chosen host, and to have oidc.verify_token accept a JWT signed with the attacker's own key.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Eclipse Foundation Eclipse CSI - PIA 服务端请求伪造漏洞
Vulnerability Description
Eclipse Foundation Eclipse CSI - PIA是Eclipse Foundation基金会的一款信息化产品。 Eclipse Foundation Eclipse CSI - PIA 0.3.0及之前版本存在服务端请求伪造漏洞,该漏洞源于OIDC issuer allowlist对Jenkins令牌的颁发者使用简单的字符串前缀检查而非验证为正确的主机绑定URL,可能导致未经身份验证的攻击者通过特制颁发者强制PIA向任意主机发出出站HTTP(S)请求,并接受由攻击者密钥签名的JWT
CVSS Information
N/A
Vulnerability Type
N/A