PT-2025-15725 · Unknown · Indieblocks

Tran Nguyen Bao Khanh

·

Publicado

2025-04-09

·

Atualizado

2025-04-09

·

CVE-2025-31009

CVSS v3.1

5.4

Média

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: IndieBlocks versions 0.13.1 and earlier
Description: The issue is related to a Server-Side Request Forgery (SSRF) vulnerability, which allows for Server Side Request Forgery. This means an attacker can potentially trick the server into making unauthorized requests.
Recommendations: For IndieBlocks versions 0.13.1 and earlier, update to a version later than 0.13.1 to resolve the issue. As a temporary workaround, consider restricting access to vulnerable API endpoints to minimize the risk of exploitation.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-31009

Produtos afetados

Indieblocks