isomorphic-git 在 1.42.0 之前版本中存在原型污染漏洞,位于 函数中。该漏洞允许恶意的 Git 服务器运营者通过在 ref 协商过程中广播包含 路径段的特制 ref 名称,从而污染 。控制 Git 服务器的攻击者可以广播一个特制的 ref,例如 ,以将后续所有网络操作重定向到攻击者控制的代理服务器。当受害者使用攻击者提供的 URL 调用 时,会导致 isomorphic-git 触发受害者的 回调,并将凭据发送给攻击者。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| isomorphic-git | isomorphic-git | 0 ~ 1.42.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet