Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46229

Опубликовано: 19 окт. 2023
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

A Server-Side Request Forgery (SSRF) flaw was found in the LangChain package due to a lack of restriction enforcement on specific internet addresses. This flaw could allow an attacker to access local services, conduct port scans, retrieve instance metadata, or interact with local network resources.

Отчет

No Red Hat products are impacted by this vulnerability as the affected package version is not used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918

EPSS

Процентиль: 99%
0.44711
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

CVSS3: 8.8
github
почти 3 года назад

LangChain Server Side Request Forgery vulnerability

EPSS

Процентиль: 99%
0.44711
Средний

8.8 High

CVSS3