漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对外部实体的文件或目录可访问
Vulnerability Title
kroki 安全漏洞
Vulnerability Description
kroki是Yuzu tech开源的一个图标创建工具。 kroki存在安全漏洞,该漏洞源于convert函数清理不足,可能导致发送请求到任意URL和泄露敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A