goproxy 版本 15.3 及更早版本未能对通过 HTTP 代理的 CONNECT 隧道请求应用基本的身份验证机制,使得未经身份验证的客户端可以绕过凭据要求。攻击者可以发出 CONNECT 请求,通过已认证的代理建立隧道而无需提供凭据,从而实现任意 TCP 流量的中继以及对受限目标地址的访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet