VDB
HIGH 8.1

GHSA-gmxh-hjfv-qc2w

Koillection has an authenticated Server-Side Request Forgery issue

Quick fix

GHSA-gmxh-hjfv-qc2w — koillection/koillection: upgrade to the fixed version with the command below.

composer require koillection/koillection:^1.8.4

Details

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / koillection/koillection
Introduced in: 0 Fixed in: 1.8.4
Fix composer require koillection/koillection:^1.8.4

References