Memos 0.30.0 及之前版本在链接元数据抓取器中的 SSRF 防护中遗漏了 100.64.0.0/10 运营商级 NAT 地址段,导致未认证的攻击者可以绕过 IP 校验。攻击者可以让服务器请求该地址段内的内部主机(包括云元数据服务),并读取返回的页面标题和描述。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet