PT-2024-40489 · Inventree · Inventree
Published
2024-10-02
·
Updated
2024-10-02
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
InvenTree versions prior to 0.16.5
InvenTree versions prior to 0.17.0
Description
The issue allows a malicious actor to potentially extract information about server-side resources by abusing the "download image from remote URL" feature. Submitting a crafted URL can raise a server-side error, which may contain sensitive information about the server-side request, including the availability of the remote resource.
Recommendations
For versions prior to 0.16.5, update to version 0.16.5 to resolve the issue.
For versions prior to 0.17.0, update to version 0.17.0 to resolve the issue.
As a temporary workaround, consider disabling the "download image from remote URL" feature in InvenTree to prevent users from accessing this information.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inventree