Plack::Middleware::Security::Common是RRWO个人开发者的一个Perl Web应用安全响应头中间件。 Plack::Middleware::Security::Common 0.13.1之前版本存在安全漏洞,该漏洞源于请求路径中的标头注入规则无效,除非标头注入被双重编码,例如GET /path HTTP/1.1 Host: secret.example.com,需要注意的是,不清楚反向代理是否会阻止带有CRLF后跟额外标头的请求路径,也不清楚基于Plack的服务器如何处理
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RRWO | Plack::Middleware::Security::Common | < 0.13.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RRWO | Plack::Middleware::Security::Common | 0 ~ 0.13.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet