在 NASA earthdata-search 1.0.0 中检测到一个漏洞。该漏洞影响的是 端点组件中 文件中的 函数。通过对该函数进行操作,可触发服务器端请求伪造(SSRF)。此攻击可远程发起。该漏洞的利用方式现已公开,并可能被用于实际攻击。厂商虽已在披露前被告知此问题,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NASA | earthdata-search | 1.0.0 |
cpe:2.3:a:nasa:earthdata-search:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet