css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued…
提示
摘要
css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attac…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/premailer/css_parser/commit/7d2ddf0189cd54b54f378f59daefa10cb036e476
- https://github.com/premailer/css_parser/commit/e0a151458b2a801ae265ba420862ef8b1127b3ae
- https://github.com/premailer/css_parser/releases/tag/v3.0.0
- https://github.com/premailer/css_parser/security/advisories/GHSA-9pmc-p236-855h
时间线
- nvd_ingest NVD