Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Vulnerability Description
Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses, allowing an authenticated user to reach loopback or link-local targets that the guard intends to block. This issue is fixed in version 10.6.15.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Amir Raminfar Dozzle 服务端请求伪造漏洞
Vulnerability Description
Amir Raminfar Dozzle是Amir Raminfar个人开发者的一款实时查看Docker容器日志的界面工具。 Amir Raminfar Dozzle 10.5.2版本至10.6.15之前版本存在服务端请求伪造漏洞,该漏洞源于isBlockedIP SSRF防护未检查嵌入在6to4、NAT64、Teredo或IPv4兼容IPv6地址中的IPv4地址,可能允许经身份验证的用户访问回环或链路本地目标。
CVSS Information
N/A
Vulnerability Type
N/A