Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67m4-qxp3-j6hh

Опубликовано: 30 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

TrueLayer.Client SSRF when fetching payment or payment provider

Impact

The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could lead to information disclosure.

Patches

Versions of TrueLayer.Client v1.6.0 and later are not affected.

Workarounds

The issue can be mitigated by having strict egress rules limiting the destinations to which requests can be made, and applying strict validation to any user input passed to the TrueLayer.Client library.

Пакеты

Наименование

TrueLayer.Client

nuget
Затронутые версииВерсия исправления

< 1.6.0

1.6.0

EPSS

Процентиль: 33%
0.0013
Низкий

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could lead to information disclosure. The issue can be mitigated by having strict egress rules limiting the destinations to which requests can be made, and applying strict validation to any user input passed to the `truelayer-dotnet` library. Versions of TrueLayer.Client `v1.6.0` and later are not affected.

EPSS

Процентиль: 33%
0.0013
Низкий

8.6 High

CVSS3

Дефекты

CWE-918