PT-2024-27764 · Strapi · Strapi
Published
2024-06-20
·
Updated
2024-10-04
·
CVE-2024-37818
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Strapi version 4.24.4
Description
The issue allows attackers to scan for open ports or access sensitive information via a crafted GET request to the "/strapi.io/ next/image" component. This is a Server-Side Request Forgery (SSRF) vulnerability. The Strapi Development Community argues that this issue is not valid, contending that the flaw only pertains to the strapi.io website and does not pose any real SSRF risk to applications using the Strapi library.
Recommendations
For Strapi version 4.24.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Strapi