pgweb 版本至 0.17.0,在配置了 connect-backend 授权的情况下,其 POST /api/connect 端点未受保护,允许攻击者提供任意的数据库连接字符串。攻击者可以通过提供自定义的会话标识符和连接 URL,绕过资源到数据库的映射,从而访问未授权的数据库和内部服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet