Webhook 在 2.8.3 及更早版本中,在评估触发规则之前会将整个请求体读入内存,这使得未经身份验证的攻击者可以通过发送过大的请求体来耗尽内存。攻击者可以发送带有无效签名的多吉字节大小的请求体,从而触发内存溢出条件并导致服务崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet