Description
txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to version 1.6.1, a Server-Side Request Forgery (SSRF) vulnerability in the `/proxy` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network. Version 1.6.1 patches the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39200 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to version 1.6.1, a Server-Side Request Forgery (SSRF) vulnerability in the `/proxy` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network. Version 1.6.1 patches the issue. |
References
History
Mon, 30 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Txtdot
Txtdot txtdot |
|
| CPEs | cpe:2.3:a:txtdot:txtdot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Txtdot
Txtdot txtdot |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-12T20:55:12.355Z
Reserved: 2024-07-22T13:57:37.137Z
Link: CVE-2024-41813
Updated: 2024-08-02T04:46:52.688Z
Status : Modified
Published: 2024-07-26T17:15:12.990
Modified: 2024-11-21T09:33:07.533
Link: CVE-2024-41813
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD