Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader
Vulnerability Description
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database endpoints or cloud instance metadata services to retrieve sensitive credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Weaviate Verba 服务端请求伪造漏洞
Vulnerability Description
Weaviate Verba是Weaviate公司开源的一款向量数据库产品。 Weaviate Verba 2.1.3及之前版本存在服务端请求伪造漏洞,该漏洞源于未经验证的服务端请求伪造,可能导致未经身份验证的攻击者通过WebSocket import endpoint提供攻击者控制的URL,使后端发出任意HTTP GET请求,获取内部资源,如数据库端点或云实例元数据服务中的敏感凭据。
CVSS Information
N/A
Vulnerability Type
N/A