以下是对该漏洞描述信息的中文翻译: 将未经信任且未进行规范化处理的用户输入直接用于指标数据(例如指标名称、标签键或标签值)是一种危险的反模式,通用型 instrumentation(监控/指标采集组件)绝不应采用此类做法。在使用此类不安全的 instrumentation 时,应用程序容易遭受注入和欺骗攻击,因为在此次修复之前, 和 默认不会在发送前对换行符( 、 )进行清理(sanitize)。 对于 中的 StatsD 注册表(当使用 Datadog 或 Etsy 格式时),由于 StatsD 协议是以换行符分
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Spring Micrometer | 1.17.0 - 1.17.0 |
affected |
1.16.0 - 1.16.6 |
affected | ||
1.15.0 - 1.15.12 |
affected | ||
1.14.0 - 1.14.16 |
affected | ||
1.9.18 and earlier |
affected | ||
1.17.0.1 |
unaffected | ||
1.17.1 |
unaffected | ||
1.16.6.1 |
unaffected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | Spring Micrometer | 1.17.0 - 1.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet