漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Microsoft UFO: IPv6 transition address bypass of SSRF guard in URL validation
Vulnerability Description
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4 destinations, allowing an unauthenticated remote attacker who can influence URLs processed by validate_url to bypass the SSRF guard and reach cloud metadata, internal services, or localhost. This issue is fixed in version 3.0.8.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Microsoft UFO 服务端请求伪造漏洞
Vulnerability Description
Microsoft UFO是美国Microsoft公司的一款Web服务器。 Microsoft UFO 3.0.8之前版本存在服务端请求伪造漏洞,该漏洞源于ufo/utils/url_security.py中的_is_blocked_ip函数未阻止NAT64、6to4和Teredo前缀,且未重新检查嵌入的IPv4目标,可能导致未经身份验证的远程攻击者绕过SSRF防护,访问云元数据、内部服务或本地主机。
CVSS Information
N/A
Vulnerability Type
N/A