漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
Vulnerability Description
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
Puma 授权问题漏洞
Vulnerability Description
puma是puma公司开源的一款运动服饰品牌。 Puma 5.5.0版本至7.2.1之前版本和8.0.0版本至8.0.2之前版本存在安全漏洞,该漏洞源于在启用set_remote_address proxy_protocol: :v1并使用持久连接时,Puma错误地重新解析同一连接上每个keep-alive请求后的PROXY协议标头,导致源IP欺骗攻击。
CVSS Information
N/A
Vulnerability Type
N/A