Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5366-4wpf-vvr9

Опубликовано: 11 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.

PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.

EPSS

Процентиль: 37%
0.00159
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.

EPSS

Процентиль: 37%
0.00159
Низкий

Дефекты

CWE-918