[GH-ISSUE #3487] 安全扫描监测到GoAhead-Server-环境变量注入漏洞 #2788

Closed
opened 2026-05-05 13:48:01 -06:00 by gitea-mirror · 2 comments
Owner

Originally created by @aiwatcher on GitHub (Jun 14, 2023).
Original GitHub issue: https://github.com/fatedier/frp/issues/3487

Bug Description

3be5c5a3f19f88452e5f7e475201089
线上系统监测到有“GoAhead-Server-环境变量注入漏洞“攻击,请确认一下是否存在此安全漏洞。

frpc Version

v0.46.0

frps Version

v0.46.0

System Architecture

linux

Configurations

开了7000端口,token认证

Logs

No response

Steps to reproduce

...

Affected area

  • Docs
  • Installation
  • Performance and Scalability
  • Security
  • User Experience
  • Test and Release
  • Developer Infrastructure
  • Client Plugin
  • Server Plugin
  • Extensions
  • Others
Originally created by @aiwatcher on GitHub (Jun 14, 2023). Original GitHub issue: https://github.com/fatedier/frp/issues/3487 ### Bug Description ![3be5c5a3f19f88452e5f7e475201089](https://github.com/fatedier/frp/assets/84110437/a11c70bb-48ce-425c-8517-aaed890ec1a4) 线上系统监测到有“GoAhead-Server-环境变量注入漏洞“攻击,请确认一下是否存在此安全漏洞。 ### frpc Version v0.46.0 ### frps Version v0.46.0 ### System Architecture linux ### Configurations 开了7000端口,token认证 ### Logs _No response_ ### Steps to reproduce 1. 2. 3. ... ### Affected area - [ ] Docs - [ ] Installation - [ ] Performance and Scalability - [ ] Security - [ ] User Experience - [ ] Test and Release - [ ] Developer Infrastructure - [ ] Client Plugin - [ ] Server Plugin - [ ] Extensions - [ ] Others
gitea-mirror 2026-05-05 13:48:01 -06:00
Author
Owner

@Becods commented on GitHub (Jun 16, 2023):

frp不使用GoAhead

c71efde303/go.mod (L1-L77)

<!-- gh-comment-id:1594350329 --> @Becods commented on GitHub (Jun 16, 2023): frp不使用GoAhead https://github.com/fatedier/frp/blob/c71efde303102cdb2a16a868391ac72c0828bee1/go.mod#L1-L77
Author
Owner

@github-actions[bot] commented on GitHub (Jul 17, 2023):

Issues go stale after 30d of inactivity. Stale issues rot after an additional 7d of inactivity and eventually close.

<!-- gh-comment-id:1637235738 --> @github-actions[bot] commented on GitHub (Jul 17, 2023): Issues go stale after 30d of inactivity. Stale issues rot after an additional 7d of inactivity and eventually close.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/frp#2788
No description provided.