Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prm2-rg4g-w438

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 8.5

Описание

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

EPSS

Процентиль: 29%
0.00353
Низкий

6.3 Medium

CVSS4

8.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.5
nvd
5 дней назад

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

EPSS

Процентиль: 29%
0.00353
Низкий

6.3 Medium

CVSS4

8.5 High

CVSS3

Дефекты

CWE-918