在 rowboatlabs 的 rowboat 0.9.1 及更早版本中检测到一处漏洞。受影响的是 Composio Webhook 端点组件中文件 里的 / 函数。对请求数据的操控可能导致拒绝服务(DoS)攻击。该攻击可远程发起。此漏洞的利用方式已公开,可能已被利用。升级到 0.9.2 版本即可解决该问题,建议升级受影响组件。在 0.9.2 版本中,旧版 Next.js 应用被直接移除而非修补,因此未留下任何安全控制机制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rowboatlabs | rowboat | 0.9.0 |
affected |
0.9.1 |
affected | ||
0.9.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rowboatlabs | rowboat | 0.9.0 |
cpe:2.3:a:rowboatlabs:rowboat:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet