中的 在存储由调用者提供的 URL 时,未进行任何地址验证,且该文件未导入任何验证辅助函数。当订阅的事件触发时, 中的 函数会使用该 URL、webhook 中记录的方法和内容类型(Content-Type),以及包含事件数据的 JSON 请求体发起 axios 请求。因此,经过身份验证的用户可以使服务器向内部端点(包括链接本地元数据地址)发送反复的、由攻击者构造的请求。该请求是“盲发”的: 会丢弃响应结果,仅将成功日志或 axios 错误写入服务器日志,因此响应不会通过 API 返回。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| omnivore-app | omnivore | < c4d7d8562e6b9aabb1d8e4dabca268e314baa43a |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| omnivore-app | omnivore | 0 ~ c4d7d8562e6b9aabb1d8e4dabca268e314baa43a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet