PT-2021-17398 · Friendica · Friendica

Parad0X-0Xff

·

Published

2021-02-18

·

Updated

2021-02-26

·

CVE-2021-27329

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Friendica version 2021.01
Description The issue allows for Server-Side Request Forgery (SSRF) via the parse url parameter with binurl for DNS lookups or HTTP requests to arbitrary domain names. This could potentially be exploited to access internal resources or make unauthorized requests.
Recommendations For Friendica version 2021.01, consider restricting access to the parse url function with the binurl parameter to minimize the risk of SSRF exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27329

Affected Products

Friendica