漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
hono/jsx does not isolate context per request, leading to cross-request data disclosure
Vulnerability Description
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Vulnerability Title
Hono 竞争条件问题漏洞
Vulnerability Description
Hono是Hono团队开源的一个用 TypeScript 编写的 Web 框架。 Hono 4.11.8版本至4.12.27之前版本存在竞争条件问题漏洞,该漏洞源于hono/jsx在服务器端渲染期间未按请求隔离环境值,允许在异步组件中await后使用来自不同进行中请求的createContext、useContext、jsxRenderer或useRequestContext数据。
CVSS Information
N/A
Vulnerability Type
N/A