PT-2022-16156 · Bookwyrm · Bookwyrm

Mouse-Reeve

·

Published

2022-02-16

·

Updated

2022-02-25

·

CVE-2022-23644

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BookWyrm versions prior to 0.3.0
Description The functionality to load a cover via URL in BookWyrm is vulnerable to a server-side request forgery attack. This issue can be exploited by a logged-in user. As a workaround, BookWyrm instances can close registration and limit members to trusted individuals.
Recommendations For versions prior to 0.3.0, upgrade to version 0.3.0 to resolve the issue. As a temporary workaround, consider closing registration and limiting members to trusted individuals to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23644
GHSA-5M7G-66H6-5CVQ

Affected Products

Bookwyrm