CVE-2024-22203
Whoogle Search Path Traversal vulnerability
描述
Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` variables and passes them to the `send` method which sends a GET request on lines 339-343 in `request.py`, which leads to a server-side request forgery. This issue allows for crafting GET requests to internal and external resources on behalf of the server. For example, this issue would allow for accessing resources on the internal network that the server has access to, even though these resources may not be accessible on the internet. This issue is fixed in version 0.8.4.
如何修補 CVE-2024-22203
要修補 CVE-2024-22203,請將受影響套件升級到下列已修補版本。
- —升級至 0.8.4 或更新版本
- —升級至 3a2e0b262e4a076a20416b45e6b6f23fd265aeda 或更新版本
CVE-2024-22203 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.8.4
- from 0, < 3a2e0b262e4a076a20416b45e6b6f23fd265aeda | from 0, < 0.8.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |