Skip to content

[Bug]: POST出现服务器端请求伪造漏洞,位置:HEADER #538

@PhuketIsland

Description

@PhuketIsland

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.12.0

Installation Type

Official Kubernetes

Service Name

DongTai-Web

Describe the details of the bug and the steps to reproduce it

image
根据调用链显示x-forwarded-for参数存在ssrf的注入点,我将洞态上的请求复制到burp上重新发从,发现将x-forwarded-for这个参数删除之后仍然可以得到响应结果,这个是不是误报?
image
image

Additional Information

No response

Logs

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions