Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x698-9g95-chp7

Опубликовано: 08 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

EPSS

Процентиль: 84%
0.02257
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

EPSS

Процентиль: 84%
0.02257
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918