cvelist/2018/1000xxx/CVE-2018-1000138.json

65 lines
1.5 KiB
JSON
Raw Normal View History

2018-03-23 12:26:56 -06:00
{
"data_version": "4.0",
"references": {
"reference_data": [
{
"url": "https://github.com/mkucej/i-librarian/issues/120"
},
{
"url": "https://github.com/mkucej/i-librarian/blob/9535753a84bc615b210802d4c9542db73368d984/functions.php#L811"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "I, Librarian version 4.8 and earlier contains a SSRF vulnerability in \"url\" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources."
}
]
},
"data_type": "CVE",
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"version": {
"version_data": [
{
"version_value": "4.8 and earlier"
}
]
},
"product_name": "I, Librarian "
}
]
},
"vendor_name": "I, Librarian "
}
]
}
},
"CVE_data_meta": {
"DATE_ASSIGNED": "3/15/2018 22:32:23",
"ID": "CVE-2018-1000138",
"ASSIGNER": "kurt@seifried.org",
"REQUESTER": "3022235906@qq.com"
},
"data_format": "MITRE",
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "SSRF"
}
]
}
]
}
}