Huly 平台在 0.7.426 及更早版本中存在服务器端请求伪造(SSRF)漏洞,原因是打印服务缺少对主机名的白名单验证。经过身份验证的工作区成员可以向打印端点传入任意 URL,Puppeteer 会渲染这些 URL 并将其返回为可下载的 PDF 或图像,从而允许访问内部元数据服务和网络主机。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hcengineering | platform | ≤ 0.7.426 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hcengineering | platform | 0 ~ 0.7.426 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet