CVE-2023-41054 Information
Description
LibreY is a fork of LibreX a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the image_proxy.php file of LibreY before commit 8f9b9803f231e2954e5b49987a532d28fe50a627. This vulnerability allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network or conduct Denial-of-Service (DoS) attacks via the url parameter. Remote attackers can use the server as a proxy to send HTTP GET requests and retrieve information in the internal network. Remote attackers can also request the server to download large files or chain requests among multiple instances to reduce the performance of the server or even deny access from legitimate users. This issue has been addressed in https://github.com/Ahwxorg/LibreY/pull/31. LibreY hosters are advised to use the latest commit. There are no known workarounds for this vulnerability.
Reference
https://github.com/Ahwxorg/LibreY/security/advisories/GHSA-p4f9-h8x8-mpwf
https://github.com/Ahwxorg/LibreY/pull/31
LibreY
is
a
fork
of
LibreX
a
framework-less
and
javascript-free
privacy
respecting
meta
search
engine.
LibreY
is
subject
to
a
Server-Side
Request
Forgery
(SSRF)
vulnerability
in
the
image_proxy.php
file
of
LibreY
before
commit
8f9b9803f231e2954e5b49987a532d28fe50a627.
This
vulnerability
allows
remote
attackers
to
use
the
server
as
a
proxy
to
send
HTTP
GET
requests
to
arbitrary
targets
and
retrieve
information
in
the
internal
network
or
conduct
Denial-of-Service
(DoS)
attacks
via
the
url
parameter.
Remote
attackers
can
use
the
server
as
a
proxy
to
send
HTTP
GET
requests
and
retrieve
information
in
the
internal
network.
Remote
attackers
can
also
request
the
server
to
download
large
files
or
chain
requests
among
multiple
instances
to
reduce
the
performance
of
the
server
or
even
deny
access
from
legitimate
users.
This
issue
has
been
addressed
in
https://github.com/Ahwxorg/LibreY/pull/31.
LibreY
hosters
are
advised
to
use
the
latest
commit.
There
are
no
known
workarounds
for
this
vulnerability.