PT-2022-18483 · Kavita · Kavita

Published

2022-08-10

·

Updated

2022-11-14

·

CVE-2022-2756

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions kareadita/kavita versions prior to 0.5.4.1
Description The issue is related to Server-Side Request Forgery (SSRF) in the GitHub repository kareadita/kavita. SSRF is a type of attack where an attacker can trick a server into making requests to internal or external resources, potentially leading to unauthorized access or data leakage.
Recommendations For versions prior to 0.5.4.1, update to version 0.5.4.1 or later to resolve the issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2756

Affected Products

Kavita