4.2.0 及更早版本存在一个缓存验证漏洞。该漏洞位于 函数中,由于采用逐字节字符串比较的方式,导致无法正确验证 头中的通配符。攻击者可以请求其他客户端之前已获取的 URL,从而收到原本面向不同用户缓存的响应,进而跨客户端泄露敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kornelski | http-cache-semantics | ≤ 4.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kornelski | http-cache-semantics | 0 ~ 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet