MLRun 1.11.0 及以下版本中存在一个服务器端请求伪造(SSRF)漏洞,位于 WebhookNotification 处理程序中。该漏洞允许经过身份验证的用户诱导 API 服务器向内部地址发送任意 HTTP 请求。攻击者可以通过更新运行记录并设置恶意的 Webhook 通知来利用此漏洞;当运行记录达到终止状态时,该通知会被触发执行,从而允许从集群内部向内部服务、Kubernetes API 或云元数据端点发起请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet