2023-05-08 18:00:27 +02:00
|
|
|
{
|
|
|
|
"id": "CVE-2023-30019",
|
|
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
|
|
"published": "2023-05-08T15:15:11.087",
|
2023-05-08 20:00:28 +02:00
|
|
|
"lastModified": "2023-05-08T16:35:01.700",
|
|
|
|
"vulnStatus": "Awaiting Analysis",
|
2023-05-08 18:00:27 +02:00
|
|
|
"descriptions": [
|
|
|
|
{
|
|
|
|
"lang": "en",
|
2023-05-08 20:00:28 +02:00
|
|
|
"value": "imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter."
|
2023-05-08 18:00:27 +02:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"metrics": {},
|
|
|
|
"references": [
|
|
|
|
{
|
|
|
|
"url": "https://breakandpray.com/cve-2023-30019-ssrf-in-imgproxy/",
|
|
|
|
"source": "cve@mitre.org"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://github.com/imgproxy/imgproxy",
|
|
|
|
"source": "cve@mitre.org"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|