Описание
ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
An issue in Ntfy ntfy.sh before v.2.22.0 allows a remote attacker to execute arbitrary code via the parseActions function.
Пакеты
Наименование
heckel.io/ntfy/v2
go
Затронутые версииВерсия исправления
< 2.22.0
2.22.0
Связанные уязвимости
CVSS3: 6.4
ubuntu
5 месяцев назад
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
CVSS3: 6.4
nvd
5 месяцев назад
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.