imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.
Title imgproxy is vulnerable to SSRF against 0.0.0.0
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-12T20:41:35.745Z

Reserved: 2025-01-20T15:18:26.988Z

Link: CVE-2025-24354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-27T18:15:41.197

Modified: 2025-01-27T18:15:41.197

Link: CVE-2025-24354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.