脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation
脆弱性説明
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
脆弱性タイプ
服务端请求伪造(SSRF)
脆弱性タイトル
Red Hat Apicurio Registry 服务端请求伪造漏洞
脆弱性説明
Red Hat Apicurio Registry是美国Red Hat公司的一款用于管理与版本控制API模式与事件数据结构的开源注册中心。 Red Hat Apicurio Registry存在服务端请求伪造漏洞,该漏洞源于WSDLReaderAccessor未禁用javax.wsdl.importDocuments特性,设置VALIDITY规则为FULL时,具有Developer角色的攻击者可通过上传包含攻击者控制导入位置的WSDL文档,导致注册表向任意内部URL发出HTTP请求。
CVSS情報
N/A
脆弱性タイプ
N/A