eventsource-encoder是Espen Hovlandsdal个人开发者的一个服务端事件编码工具。 eventsource-encoder 1.0.2之前版本存在注入漏洞,该漏洞源于序列化EventSourceMessage时未清理事件或ID字段,攻击者控制任一字段可注入任意服务器发送事件行终止符,从而伪造额外SSE字段或消息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rexxars | eventsource-encoder | < 1.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rexxars | eventsource-encoder | < 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet