kin-openapi 是一个用于处理 OpenAPI 文件的 Go 项目。在版本 0.10.0 至 0.141.0 期间, 中的 函数在解引用 之前,未检查 是否为 nil。当 multipart/form-data 请求体的非字符串标量字段格式错误时,会生成一个嵌套的 ParseError,其 为 nil;若应用程序通过 或 渲染该验证错误,则会导致 panic。如果应用缺乏恢复机制(recovery boundary),未经身份验证的客户端可反复发送此类请求,从而导致服务拒绝。JSON 请求体以及未使用这些错
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getkin | kin-openapi | >= 0.10.0, < 0.141.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getkin | kin-openapi | >= 0.10.0, < 0.141.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet