在 Eclipse Che 7.29.0 及更高版本中,GET 和 POST 端点会将攻击者控制的 URL 传递给 方法。该方法调用 ,且未对 URL 的协议(scheme)或主机(host)进行白名单校验,并将响应正文返回给调用者。 任何经过身份验证的 Che 用户均可利用 file:// 协议读取任意本地文件(包括 Kubernetes Pod 中的 ServiceAccount 令牌,路径为 ),访问内部 HTTP 服务以及云实例元数据端点(如 169.254.169.254),并可以将其存储的 SCM 个人
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Che | 7.29.0 ~ 7.123.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet