Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Astro: Unauthenticated path override in the @astrojs/vercel ISR function
Vulnerability Description
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes protected only by Vercel edge path rules or split edge middleware. This issue is fixed in 11.0.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
未有动机的代理或中间人(混淆代理)
Vulnerability Title
Astro 服务端请求伪造漏洞
Vulnerability Description
Astro Astro是Astro组织开源的一个内容驱动网站的 web 框架。 Astro 10.0.3版本至11.0.3之前版本存在安全漏洞,该漏洞源于packages/integrations/vercel/src/serverless/entrypoint.ts中Astro Vercel适配器仅根据x-vercel-isr标头接受x_astro_path,可能导致未经身份验证的攻击者通过GET请求渲染受Vercel边缘路径规则或拆分边缘中间件保护的路由。
CVSS Information
N/A
Vulnerability Type
N/A