WeKnora 在 0.7.0 之前的版本中,在通过 端点从用户提供的 URL 下载文档时,未能重新验证 HTTP 重定向的目标地址。经过认证的恶意用户可以利用指向内网地址的公共 URL 来绕过初始的 SSRF 验证,从而实现对内部服务和云元数据的访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet