Eclipse Foundation Eclipse CSI - PIA是Eclipse Foundation基金会的一款信息化产品。 Eclipse Foundation Eclipse CSI - PIA 0.3.0及之前版本存在服务端请求伪造漏洞,该漏洞源于OIDC issuer allowlist对Jenkins令牌的颁发者使用简单的字符串前缀检查而非验证为正确的主机绑定URL,可能导致未经身份验证的攻击者通过特制颁发者强制PIA向任意主机发出出站HTTP(S)请求,并接受由攻击者密钥签名的JWT
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse CSI - PIA | ≤ 0.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse CSI - PIA | 0 ~ 0.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet