PT-2022-15643 · Partkeepr · Partkeepr

Alestorm980

·

Published

2022-01-07

·

Updated

2025-07-01

·

CVE-2022-22702

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PartKeepr versions up to v1.4.0
Description The issue allows an authenticated user to carry out SSRF (Server-Side Request Forgery) attacks and port enumeration due to a lack of validation in the functionality to upload attachments using a URL when creating a part. This enables requests to be made to local ports.
Recommendations For versions up to v1.4.0, update to a version that contains a fix for this issue to prevent SSRF attacks and port enumeration.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-22702

Affected Products

Partkeepr