PT-2024-29579 · Txtdot · Txtdot
Ouuan
·
Published
2024-07-26
·
Updated
2024-09-30
·
CVE-2024-41812
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
txtdot versions prior to 1.7.0
txtdot version 1.7.0
Description
The issue concerns a Server-Side Request Forgery (SSRF) vulnerability in the
/get route, allowing remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network.Recommendations
For versions prior to 1.7.0, update to version 1.7.0 or later.
For version 1.7.0, set a firewall between txtdot and other internal network resources to prevent exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Txtdot