Количество 2
Количество 2
CVE-2024-32964
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.
GHSA-mxhq-xw3g-rphc
lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-32964 Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information. | CVSS3: 9 | 54% Средний | больше 1 года назад | |
GHSA-mxhq-xw3g-rphc lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability | CVSS3: 9 | 54% Средний | больше 1 года назад |
Уязвимостей на страницу