漏洞描述
9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src/dashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/advisories/GHSA-5mj8-gf6m-fhw8↗github.comhttps://github.com/decolua/9router/security/advisories/GHSA-5mj8-gf6m-fhw8↗github.comhttps://github.com/decolua/9router/commit/efd20be8d81ef2e256a7037f3aa78e6b567b5fd3↗github.comhttps://github.com/decolua/9router/releases/tag/v0.5.6↗