PT-2021-11966 · Tinycheck · Tinycheck

Published

2021-01-21

·

Updated

2021-02-02

·

CVE-2020-36200

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: TinyCheck versions before 9fd360d and ea53de8
Description: The issue allows an authenticated attacker to send an HTTP GET request to crafted URLs.
Recommendations: For versions before 9fd360d and ea53de8, update to a version that includes commits 9fd360d and ea53de8 to resolve the issue.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36200
GHSA-GQPW-3669-6W5H

Affected Products

Tinycheck