Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
NVIDIA NeMoClaw 代码问题漏洞
Vulnerability Description
NVIDIA NeMoClaw是美国英伟达(NVIDIA)公司的一个大模型行为约束与安全控制框架。 NVIDIA NemoClaw存在代码问题漏洞,该漏洞源于validateEndpointUrl() SSRF保护组件问题,可能导致攻击者通过蓝图配置文件或CLI标志提供引用0.0.0.0/8地址范围的恶意端点URL,造成服务器端请求伪造,成功利用此漏洞可能导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A