Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23644

Опубликовано: 16 фев. 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a logged-in user. The problem has been patched and administrators should upgrade to version 0.3.0 As a workaround, BookWyrm instances can close registration and limit members to trusted individuals.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:joinbookwyrm:bookwyrm:*:*:*:*:*:*:*:*
Версия до 0.3.0 (исключая)

EPSS

Процентиль: 53%
0.00299
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-918

EPSS

Процентиль: 53%
0.00299
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-918