漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
Vulnerability Description
Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <enclosure url="..."> values extracted from the RSS XML are stored directly into the database without any SSRF validation. When a user plays an episode, the server downloads the full HTTP response from the unvalidated enclosure URL via Http::sink()->get() and streams it back to the user, enabling full-read SSRF against internal services. This issue has been patched in version 9.3.5.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Koel 服务端请求伪造漏洞
Vulnerability Description
Koel是koel个人开发者开源的一个基于Web的个人音频流服务。 Koel 9.3.5之前版本存在服务端请求伪造漏洞,该漏洞源于在验证播客订阅源URL时未对RSS XML中的enclosure URL进行服务端请求伪造验证,可能导致用户播放剧集时服务器从未经验证的URL下载完整HTTP响应并流式返回给用户,造成对内部服务的完全读取型SSRF攻击。
CVSS Information
N/A
Vulnerability Type
N/A