Описание
BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a logged-in user. The problem has been patched and administrators should upgrade to version 0.3.0 As a workaround, BookWyrm instances can close registration and limit members to trusted individuals.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.3.0 (исключая)
cpe:2.3:a:joinbookwyrm:bookwyrm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00299
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-918
EPSS
Процентиль: 53%
0.00299
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-918