Описание
Paranoidhttp Server-Side Request Forgery vulnerability
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-24623
- https://github.com/hakobe/paranoidhttp/commit/07f671da14ce63a80f4e52432b32e8d178d75fd3
- https://github.com/hakobe/paranoidhttp/blob/master/CHANGELOG.md#v030-2023-01-19
- https://github.com/hakobe/paranoidhttp/compare/v0.2.0...v0.3.0
- https://pkg.go.dev/vuln/GO-2023-1526
Пакеты
Наименование
github.com/hakobe/paranoidhttp
go
Затронутые версииВерсия исправления
< 0.3.0
0.3.0
Связанные уязвимости
CVSS3: 7.5
nvd
около 3 лет назад
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.