Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8rr-9cvg-cx5j

Опубликовано: 02 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during the initial setup window, causing the server to issue HTTP GET requests to internal or reserved addresses and leak information through echoed connection-error messages.

AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during the initial setup window, causing the server to issue HTTP GET requests to internal or reserved addresses and leak information through echoed connection-error messages.

EPSS

Процентиль: 41%
0.00505
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.8
nvd
около 2 месяцев назад

AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during the initial setup window, causing the server to issue HTTP GET requests to internal or reserved addresses and leak information through echoed connection-error messages.

EPSS

Процентиль: 41%
0.00505
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-918