以下是该漏洞描述的中文翻译: HTTP 请求/响应走私漏洞(HTTP Request/Response Smuggling) elixir-mint 的 库中存在一个 HTTP 请求/响应走私漏洞。攻击者可利用此漏洞,通过恶意 HTTP/1 服务器导致严格的中间代理与 Mint 客户端在连接池共享连接上出现状态不同步,从而对后续复用该连接的请求实施“响应队列投毒”(response-queue poisoning)攻击。 技术细节: 中的 函数在解析分块响应(chunked response)的 行时,遇到第一个非
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| elixir-mint | mint | 0.1.0< 1.10.1 |
affected |
60089586ec7adc9fddb09f69a2f5919ba9ac7f33< c82377838dc6e275ef40bafa664fbcdf50270c60 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-mint | mint | 0.1.0 ~ 1.10.1 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| elixir-mint | mint | 60089586ec7adc9fddb09f69a2f5919ba9ac7f33 ~ c82377838dc6e275ef40bafa664fbcdf50270c60 |
cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet