Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting
Vulnerability Description
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment. A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to services running behind nginx reverse proxies, and then set the X-Accel-Mapping to map the path to an arbitrary file on the server. Since 1.0053, Plack::Middleware::XSendfile is deprecated and will be removed from future releases of Plack. This is similar to CVE-2025-61780 for Rack::Sendfile, although Plack::Middleware::XSendfile has some mitigations that disallow regular expressions to be used in the mapping, and only apply the mapping for the "X-Accel-Redirect" type.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Plack::Middleware::XSendfile 信息泄露漏洞
Vulnerability Description
Plack::Middleware::XSendfile是MIYAGAWA个人开发者的一个为Web应用提供高效文件传输支持的中间件组件。 Plack::Middleware::XSendfile 1.0053及之前版本存在信息泄露漏洞,该漏洞源于允许客户端通过X-Sendfile-Type标头控制路径重写,可能导致恶意客户端设置X-Accel-Redirect类型并映射到任意文件。
CVSS Information
N/A
Vulnerability Type
N/A