LinuxServerio heimdall 263-ls307 contains a vulnerability in how it handles user-supplied HTTP

链接: https://github.com/advisories/GHSA-2c6m-gpf4-cfgp

CVSS 评分: 9.8

参考链接:

描述:

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically X-Forwarded-Host and Referer. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.


LinuxServerio heimdall 263-ls307 contains a vulnerability in how it handles user-supplied HTTP
http://example.com/2025/07/30/github_230030136/
作者
lianccc
发布于
2025年7月30日
许可协议