Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses
Vulnerability Description
Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead.
CVSS Information
N/A
Vulnerability Type
敏感数据的明文传输
Vulnerability Title
Plack::Middleware::Statsd 安全漏洞
Vulnerability Description
Plack::Middleware::Statsd是Robert Rothenberg个人开发者的一个用于记录 Web 请求指标并发送至统计系统的中间件组件。 Plack::Middleware::Statsd 0.9.0之前版本存在安全漏洞,该漏洞源于与statsd守护进程的通信信道未加密,可能导致用户IP地址泄露。
CVSS Information
N/A
Vulnerability Type
N/A