在 ddfourtwo sentry-selfhosted-mcp 0.4.0 中发现了一个安全漏洞。受影响的是组件 中的一个未知函数。对参数 的操作会导致服务器端请求伪造(SSRF)漏洞。该攻击可远程发起。利用该漏洞的代码已公开,可能被用于发动攻击。项目方已通过问题报告提前获知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ddfourtwo | sentry-selfhosted-mcp | 0.4.0 |
cpe:2.3:a:ddfourtwo:sentry-selfhosted-mcp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet