CVE-2022-23071 Information
Jun 20, 2022
cve
Description
In Recipes versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF) in the “Import Recipe” functionality. When an attacker enters the localhost URL a low privileged attacker can access/read the internal file system to access sensitive information.
Reference
https://www.mend.io/vulnerability-database/CVE-2022-23071 https://github.com/TandoorRecipes/recipes/commit/d48fe26a3529cc1ee903ffb2758dfd8f7efaba8c
Share on: