Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9x7h-ggc3-xg47: imgproxy is vulnerable to Server-Side Request Forgery

imgproxy prior to version 3.15.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

ghsa
#git#ssrf

imgproxy is vulnerable to Server-Side Request Forgery

Moderate severity GitHub Reviewed Published May 8, 2023 to the GitHub Advisory Database • Updated May 11, 2023

Related news

CVE-2023-30019: CVE-2023-30019: SSRF in imgproxy<=3.14.0

imgproxy <= 3.6.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.