漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Vulnerability Description
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Processing an attacker-controlled OpenAPI description can cause requests from the developer or CI host to attacker-selected or internal HTTP services, read absolute or out-of-tree local files, and inline untrusted remote schemas into generated clients. The affected code is packages/orval/src/import-specs.ts external reference loading. This issue is fixed in version 8.22.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
orval-labs orval 路径遍历漏洞
Vulnerability Description
orval-labs orval是orval-labs组织的一款服务器设备与网络产品。 orval-labs orval 8.22.0之前版本存在安全漏洞,该漏洞源于外部引用加载时未对远程和本地外部$ref值进行白名单验证或限制输入目录,可能导致处理攻击者控制的OpenAPI描述时向攻击者选择或内部HTTP服务发起请求、读取绝对或项目目录外的本地文件,并将不受信任的远程模式内联到生成的客户端中。
CVSS Information
N/A
Vulnerability Type
N/A