版本 1.11.0 之前的 Open Notebook 在 端点中未能验证 URL 参数,使得经过身份验证的用户能够向内部服务发起服务端请求。攻击者可以通过应用服务器的直接 HTTP 请求,提供任意 URL 来读取云元数据、内部网络服务以及与本地主机绑定的服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lfnovo | open-notebook | < 1.11.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| lfnovo | open-notebook | 0 ~ 1.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet