Описание
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/resolute | needs-triage | |
| jammy | DNE | |
| noble | DNE | |
| questing | ignored | end of life, was needs-triage |
| resolute | needs-triage | |
| upstream | needs-triage |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 19%
0.00272
Низкий
6.4 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.4
nvd
5 месяцев назад
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
CVSS3: 9.8
github
5 месяцев назад
ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
EPSS
Процентиль: 19%
0.00272
Низкий
6.4 Medium
CVSS3