OpenMAIC 在 1.0.1 之前,在非生产环境中会跳过服务端请求伪造(SSRF)验证,这使得未认证的 attacker 能够访问云实例元数据服务。攻击者可以通过 请求头或 参数提供任意云服务商的 URL,从而访问敏感的云凭据和元数据信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet