PT-2024-40489 · Inventree · Inventree

Published

2024-10-02

·

Updated

2024-10-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions InvenTree versions prior to 0.16.5 InvenTree versions prior to 0.17.0
Description The issue allows a malicious actor to potentially extract information about server-side resources by abusing the "download image from remote URL" feature. Submitting a crafted URL can raise a server-side error, which may contain sensitive information about the server-side request, including the availability of the remote resource.
Recommendations For versions prior to 0.16.5, update to version 0.16.5 to resolve the issue. For versions prior to 0.17.0, update to version 0.17.0 to resolve the issue. As a temporary workaround, consider disabling the "download image from remote URL" feature in InvenTree to prevent users from accessing this information.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-VX3H-QWQW-R2WQ

Affected Products

Inventree