Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Vulnerability Description
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Prebid Server 服务端请求伪造漏洞
Vulnerability Description
Prebid Prebid Server是Prebid组织开源的一款开源服务端实时广告竞价引擎,将Header Bidding拍卖从浏览器移至云端运行。 Prebid Server 4.4.0之前版本存在服务端请求伪造漏洞,该漏洞源于bidder适配器将用户提供的参数插入出站请求URL时未正确验证主机和子域值,可能导致特制请求参数导致服务端请求到非预期目的地,暴露内部网络服务或敏感端点。
CVSS Information
N/A
Vulnerability Type
N/A