Описание
stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a malicious user to gain access to internal servers, the AWS metadata endpoint, and capture Supabase data.
Ссылки
- ExploitTechnical Description
- ExploitTechnical Description
Уязвимые конфигурации
EPSS
8.6 High
CVSS3
8.6 High
CVSS3
Дефекты
Связанные уязвимости
stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a malicious user to gain access to internal servers, the AWS metadata endpoint, and capture Supabase data.
EPSS
8.6 High
CVSS3
8.6 High
CVSS3