在 evanchiu serverless-todo 1.0.3/2.0.0 版本中发现了一个漏洞。受影响的是组件“API Todo Endpoint”中 文件里的 函数。对参数 的不当处理会导致资源消耗(如 CPU 或内存的过度使用)。该攻击可远程执行,且利用方式(Exploit)已公开,可能被实际利用。项目方已通过问题报告(Issue Report)提前得知该问题,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| evanchiu | serverless-todo | 1.0.3 |
affected |
2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| evanchiu | serverless-todo | 1.0.3 |
cpe:2.3:a:evanchiu:serverless-todo:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet