PT-2024-37222 · Quivr · Quivr
Published
2024-06-27
·
Updated
2024-08-20
·
CVE-2024-5885
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
stangirard/quivr version 0.0.236
Description:
The application contains a Server-Side Request Forgery (SSRF) vulnerability due to insufficient controls when crawling a website. This allows an attacker to access applications on the local network, potentially gaining access to internal servers, the AWS metadata endpoint, and capturing Supabase data.
Recommendations:
For version 0.0.236, consider restricting access to the crawling functionality until a patch is available. As a temporary workaround, limit the application's ability to access internal servers and sensitive endpoints like the AWS metadata endpoint. Avoid using the application for crawling websites that could potentially expose internal network resources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quivr