Логотип exploitDog
bind:CVE-2024-12392
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-12392

Количество 3

Количество 3

nvd логотип

CVE-2024-12392

11 месяцев назад

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5mh3-rhm7-jxx3

11 месяцев назад

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-00817

больше 1 года назад

Уязвимость функции загрузки данных из архива научных статей arxiv приложения машинного обучения GPT Academic, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-12392

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-5mh3-rhm7-jxx3

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-00817

Уязвимость функции загрузки данных из архива научных статей arxiv приложения машинного обучения GPT Academic, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу