Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
Vulnerability Description
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems. Version 2.3.0 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Sync-in server 服务端请求伪造漏洞
Vulnerability Description
Sync-in server是Sync-in的服务器设备。 Sync-in server 2.3.0之前版本存在服务端请求伪造漏洞,该漏洞源于URL下载功能使用的私有IP黑名单正则表达式不匹配IPv4映射的IPv6地址,可能导致SSRF保护被绕过。
CVSS Information
N/A
Vulnerability Type
N/A