Parseable 是一个专为高吞吐量数据摄入与分析设计的日志分析平台。在 3.0.0 版本之前, 文件在身份验证之前解析 请求头时使用了 方法。远程未认证的攻击者可以通过提供非 UTF-8 编码的请求头数据、格式错误的 JSON 或无效的派生请求头值,触发 Rust panic 并中断请求处理流程,从而通过反复发送请求实施拒绝服务攻击,或导致容器陷入重启循环。该问题已在 3.0.0 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| parseablehq | parseable | < 3.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| parseablehq | parseable | < 3.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet