Netty 4.1.133.Final 至 4.1.137.Final 以及 4.2.13.Final 至 4.2.17.Final 版本未能正确验证 Transfer-Encoding 请求头中的最终传输编码,使得攻击者可以利用格式错误的编码声明进行请求走私(Request Smuggling)。攻击者可以将 Transfer-Encoding 请求头拆分到多行,或使用如 "chunked, xchunked" 这样的值来绕过验证,并在最终编码不是 chunked 的情况下,将消息解码为 chunked 编码,从
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet