Portkey AI Gateway 版本 1.15.2 及更早版本存在服务器端请求伪造(SSRF)漏洞,该漏洞位于 路由中,原因是该路由缺少 中间件。攻击者可以通过设置 头部为内部地址,并转发带有 头的请求,从而访问内部服务并窃取提供商的 API 密钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Portkey-AI | gateway | 1.14.0≤ 1.15.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Portkey-AI | gateway | 1.14.0 ~ 1.15.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet