Логотип exploitDog
bind:CVE-2024-32965
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-32965

Количество 2

Количество 2

nvd логотип

CVE-2024-32965

около 1 года назад

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitive information. The jwt token header X-Lobe-Chat-Auth strored proxy address and OpenAI API Key, can be modified to scan an internal network in the target lobe-web environment. This issue has been addressed in release version 1.19.13 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2xcc-vm3f-m8rw

около 1 года назад

@lobehub/chat Server Side Request Forgery vulnerability

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-32965

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitive information. The jwt token header X-Lobe-Chat-Auth strored proxy address and OpenAI API Key, can be modified to scan an internal network in the target lobe-web environment. This issue has been addressed in release version 1.19.13 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2xcc-vm3f-m8rw

@lobehub/chat Server Side Request Forgery vulnerability

CVSS3: 8.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу