PT-2022-13423 · Unknown · Calibre-Web

Published

2022-03-07

·

Updated

2024-11-19

·

CVE-2022-0767

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions calibre-web versions prior to 0.6.17
Description The issue is related to Server-Side Request Forgery (SSRF) due to incomplete protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to localhost.
Recommendations For versions prior to 0.6.17, update to version 0.6.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP redirect functionality to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-0767
GHSA-H65G-JFQG-2W6M

Affected Products

Calibre-Web