Bisheng 版本 2.6.0-fix2 及之前版本存在服务器端请求伪造(SSRF)漏洞,位于 POST /api/v1/workflow/report/callback 接口。该接口未启用身份验证,且未对 URL 协议类型和主机进行过滤。未认证的 attackers 可提交任意 URL 以枚举内网服务和云元数据端点,并通过调用者提供的对象名称从对象存储中获取捕获到的响应内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dataelement | bisheng | ≤ 2.6.0-fix2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dataelement | bisheng | 0 ~ 2.6.0-fix2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet