Description
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.
No analysis available yet.
Remediation
Vendor Solution
Update version to 1.2.6 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28178 | In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-17T02:16:41.615Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-23071
No data.
Status : Modified
Published: 2022-06-19T11:15:07.810
Modified: 2024-11-21T06:47:55.497
Link: CVE-2022-23071
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD