txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to version 1.6.1, a Server-Side Request Forgery (SSRF) vulnerability in the `/proxy` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network. Version 1.6.1 patches the issue.
History

Mon, 30 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Txtdot
Txtdot txtdot
CPEs cpe:2.3:a:txtdot:txtdot:*:*:*:*:*:*:*:*
Vendors & Products Txtdot
Txtdot txtdot

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-07-26T16:51:33.606Z

Updated: 2024-08-12T20:55:12.355Z

Reserved: 2024-07-22T13:57:37.137Z

Link: CVE-2024-41813

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:52.688Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-26T17:15:12.990

Modified: 2024-09-30T20:02:25.837

Link: CVE-2024-41813

cve-icon Redhat

No data.