Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middleware responsible for restricting access to the endpoints uses the `Host` HTTP header rather than the actual network socket port. Versions 3.4.0 and 4.2.0 patch the issue. If an immediate upgrade to a patched version is not possible, add explicit ASP.NET Core authorization (`RequireAuthorization`) to all sensitive actuator endpoints as a defense-in-depth measure independent of port isolation and/or configure the reverse proxy or load balancer to enforce the `Host` header value and prevent clients from setting an arbitrary port.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
使用候选路径或通道进行的认证绕过
Vulnerability Title
SteeltoeOSS Steeltoe.Management.Endpoint 授权问题漏洞
Vulnerability Description
SteeltoeOSS Steeltoe.Management.Endpoint是SteeltoeOSS的一个应用程序管理端点组件。 SteeltoeOSS Steeltoe.Management.Endpoint 4.2.0之前版本和Steeltoe.Management.EndpointCore 3.2.2版本至3.4.0之前版本存在授权问题漏洞,该漏洞源于中间件使用Host HTTP标头而非实际网络套接字端口来限制端点访问,可能导致未经身份验证的攻击者通过网络访问绕过访问控制,获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A