漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Spring WS SSRF via unvalidated WS-Addressing reply destinations
Vulnerability Description
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
VMware Spring Web Services 代码问题漏洞
Vulnerability Description
VMware Spring Web Services是美国威睿(VMware)公司的一个SOAP Web服务开发框架。 VMware Spring Web Services 5.0.0至5.0.1版本、4.1.0至4.1.3版本、4.0.0至4.0.18版本和3.1.0至3.1.8版本存在代码问题漏洞,该漏洞源于WS-Addressing使用非匿名地址时可能发起未验证的出站连接。
CVSS Information
N/A
Vulnerability Type
N/A