PT-2023-18544 · Rsshub · Rsshub

Dwisiswant0

·

Publicado

2023-01-11

·

Atualizado

2023-03-07

·

CVE-2023-22493

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions RSSHub (affected versions not specified)
Description RSSHub is an open source RSS feed generator that is vulnerable to Server-Side Request Forgery (SSRF) attacks. This issue allows an attacker to send arbitrary HTTP requests from the server to other servers or resources on the network. An attacker can exploit this vulnerability by sending a request to the affected routes with a malicious URL, potentially gaining access to sensitive information that would not normally be accessible and amplifying the impact of the attack. For example, an attacker can use URL-encoded characters, such as %2F and %23, to modify the base URL and send requests to internal or other servers or resources on the network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22493
GHSA-64WP-JH9P-5CG2

Produtos afetados

Rsshub