Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5hc-wm3g-hjw6

Опубликовано: 01 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Server-Side Request Forgery (SSRF) in rudloff/alltube

Impact

Releases prior to 3.0.2 are vulnerable to a Server-Side Request Forgery vulnerability that allows an attacker to send a request to an internal hostname.

Patches

3.0.2 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.)

Part of the fix requires applying a patch to youtube-dl to prevent it from following HTTP redirects. If you are using the version of youtube-dl bundled with 3.0.2, it is already patched. However, if you are using your own unpatched version of youtube-dl you might still be vulnerable.

References

Пакеты

Наименование

rudloff/alltube

composer
Затронутые версииВерсия исправления

< 3.0.2

3.0.2

EPSS

Процентиль: 74%
0.00847
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.1
nvd
почти 4 года назад

Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

EPSS

Процентиль: 74%
0.00847
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918