脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Incus blind SSRF via image import preflight HEAD request
脆弱性説明
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be rejected by policy. Although the actual image download is blocked by the project restriction, an authenticated user can coerce the daemon into making blind HEAD requests to arbitrary destinations. These requests include server metadata in custom headers (Incus-Server-Architectures, Incus-Server-Version), which discloses information about the host environment to the attacker-controlled endpoint. This blind SSRF primitive can be used to probe internal services, unroutable address space, or cloud metadata endpoints reachable from the host. This vulnerability pattern is similar to CVE-2026-24767. This issue has been fixed in version 7.0.0.
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
脆弱性タイプ
服务端请求伪造(SSRF)
脆弱性タイトル
Incus 代码问题漏洞
脆弱性説明
Incus是LXC开源的一个系统容器和虚拟机管理器。 Incus 7.0.0之前版本存在代码问题漏洞,该漏洞源于镜像导入流程在验证项目限制之前向用户提供的URL发出出站HEAD请求,可能导致经过身份验证的用户强制守护进程向任意目的地发送盲SSRF请求,并泄露服务器元数据。
CVSS情報
N/A
脆弱性タイプ
N/A