Description
An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1250 | An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to. |
Github GHSA |
GHSA-x832-r2rj-4g5p | SSRF in Kitodo.Presentation |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:29:01.013Z
Reserved: 2022-02-13T00:00:00.000Z
Link: CVE-2022-24980
No data.
Status : Modified
Published: 2022-02-19T04:15:07.037
Modified: 2024-11-21T06:51:29.887
Link: CVE-2022-24980
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA