CVE-2023-32750
08.06.2023, 21:15
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.
Vendor | Product | Version |
---|---|---|
pydio | cells | 𝑥 < 3.0.12 |
pydio | cells | 4.1.0 ≤ 𝑥 < 4.1.3 |
𝑥
= Vulnerable software versions
References