漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Mod_proxy_cluster: mod_proxy_cluster: response body corruption via crlf injection
Vulnerability Description
A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configuration, an attacker can corrupt the response body of INFO endpoint responses. Exploitation requires network access to the MCMP protocol port, but no authentication is needed.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Vulnerability Title
mod_cluster 注入漏洞
Vulnerability Description
mod_cluster是mod_cluster项目的一个基于httpd的负载均衡器。 mod_cluster存在注入漏洞,该漏洞源于decodeenc函数存在CRLF注入,可能导致绕过输入验证。
CVSS Information
N/A
Vulnerability Type
N/A