HIGH7.5
GHSA-hxgx-584x-vwm8
Appwrite Server-Side Request Forgery vulnerability
Details
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component `/v1/avatars/favicon`. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/appwrite/server-ce
Introduced in:
0No fixed version published yet for appwrite/server-ce (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-27159[ADVISORY]
- https://gist.github.com/b33t1e/43b26c31e895baf7e7aea2dbf9743a9a[WEB]
- https://gist.github.com/b33t1e/e9e8192317c111e7897e04d2f9bf5fdb[WEB]
- https://github.com/appwrite/appwrite[PACKAGE]
- https://notes.sjtu.edu.cn/gMNlpByZSDiwrl9uZyHTKA[WEB]
- http://appwrite.com[WEB]