Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass
Vulnerability Description
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and port parameters to the /api/connect endpoint to cause the server to issue outbound GET requests to attacker-controlled infrastructure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Weaviate Verba 服务端请求伪造漏洞
Vulnerability Description
Weaviate Verba是Weaviate公司开源的一款向量数据库产品。 Weaviate Verba 2.1.3版本存在服务端请求伪造漏洞,该漏洞源于服务器端请求伪造和同源中间件绕过,允许未经身份验证的远程攻击者通过提供特制Origin标头和攻击者控制的主机及端口值,使服务器发出任意HTTP请求,攻击者可绕过API中间件的本地主机来源检查,向/api/connect端点提交任意主机和端口参数,导致服务器向攻击者控制的基础设施发出出站GET请求。
CVSS Information
N/A
Vulnerability Type
N/A