Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-32750

Опубликовано: 08 июн. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pydio:cells:*:*:*:*:*:*:*:*
Версия до 3.0.12 (исключая)
cpe:2.3:a:pydio:cells:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.3 (исключая)

EPSS

Процентиль: 84%
0.02257
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918
CWE-918

Связанные уязвимости

CVSS3: 6.5
github
больше 2 лет назад

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

EPSS

Процентиль: 84%
0.02257
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918
CWE-918