DataGear 6.0.0 及更早版本中, 端点存在服务器端请求伪造(SSRF)漏洞。该漏洞允许未认证的攻击者通过提供由调用方控制的 URI,向内部端点和云元数据服务发起任意的 HTTP 请求(GET、POST、PUT、PATCH 或 DELETE),并在无认证或校验的情况下获取完整的响应体。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| datageartech | datagear | 0 ~ 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet