Описание
Recipes version 1.5.10 allows arbitrary HTTP requests to be made
through the server. This is possible because the application is
vulnerable to SSRF.
Ссылки
- ExploitVendor Advisory
- Product
- ExploitVendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:tandoor:recipes:1.5.10:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00224
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 5.3
github
почти 2 года назад
Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.
EPSS
Процентиль: 45%
0.00224
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-918