Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-44139 PoC — Alibaba Sentinel 代码问题漏洞

Source
Associated Vulnerability
Title:Alibaba Sentinel 代码问题漏洞 (CVE-2021-44139)
Description:Alibaba Sentinel是中国阿里巴巴(Alibaba)公司的一个面向云原生微服务的高可用开源流控防护组件。 Alibaba Sentinel 1.8.2版本存在安全漏洞。攻击者利用该漏洞可以进行服务器端请求伪造攻击。
Description
There is a Pre-Auth SSRF vulnerability in Alibaba Sentinel version 1.8.2, which allows remote unauthenticated attackers to perform SSRF attacks via the /registry/machine endpoint through the ip parameter.
File Snapshot

id: CVE-2021-44139 info: name: Alibaba Sentinel - Server-side request forgery (SSRF) author: Dh ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.