Gitingest 0.3.1 及更早版本在 中未能正确验证主机名,无论是否在已知主机列表中,都会接受任何带有 、 或 前缀的主机名。攻击者可以提交带有攻击者控制的主机名的 URL,从而触发指向任意主机的出站连接,并通过 HTTP 基本认证信息泄露 GitHub 个人访问令牌(PAT)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coderamp-labs | gitingest | ≤ 0.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coderamp-labs | gitingest | 0 ~ 0.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet