漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections
Vulnerability Description
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that version 0.9.0 fixed a similar issue CVE-2026-46719 for metric names.
CVSS Information
N/A
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Vulnerability Title
Net::Statsd::Lite 注入漏洞
Vulnerability Description
Net::Statsd::Lite是Robert Rothenberg个人开发者的一款支持多指标数据包的轻量级 StatsD 客户端 Net::Statsd::Lite 0.10.0及之前版本存在注入漏洞,该漏洞源于set_add方法未检查换行符、冒号或管道,可能导致指标注入。
CVSS Information
N/A
Vulnerability Type
N/A