Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12775

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API POST /console/api/workspaces/current/tool-provider/api/test/pre. Attackers can set the url in the servers dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:langgenius:dify:0.10.1:*:*:*:*:node.js:*:*

EPSS

Процентиль: 29%
0.00103
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
github
11 месяцев назад

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.

EPSS

Процентиль: 29%
0.00103
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918