目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-27163— request-baskets 代码问题漏洞

一分钟漏洞结论

影响对象
n/a n/a
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

request-baskets是rbaskets开源的一个Web服务。 request-baskets v1.2.1版本及之前版本存在安全漏洞,该漏洞源于通过组件/api/baskets/{name}发现包含服务器端请求伪造 (SSRF)漏洞。攻击者利用该漏洞通过特制的API请求访问网络资源和敏感信息。

AI 预测 8.1 利用难度: 较易 EPSS 6.59% · P94

公开利用映射 1

影响版本矩阵 1

厂商产品 版本范围状态
n/a n/a n/a affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2023-27163 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
request-baskets 代码问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
request-baskets是rbaskets开源的一个Web服务。 request-baskets v1.2.1版本及之前版本存在安全漏洞,该漏洞源于通过组件/api/baskets/{name}发现包含服务器端请求伪造 (SSRF)漏洞。攻击者利用该漏洞通过特制的API请求访问网络资源和敏感信息。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
- n/a n/a -

二、漏洞 CVE-2023-27163 的公开POC

# POC 描述 源链接 神龙链接
1 Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1) https://github.com/entr0pie/CVE-2023-27163 POC详情
2 To assist in enumerating the webserver behind the webserver SSRF CVE-2023-27163 https://github.com/seanrdev/cve-2023-27163 POC详情
3 CVE-2023-27163 https://github.com/overgrowncarrot1/CVE-2023-27163 POC详情
4 Poc of SSRF for Request-Baskets (CVE-2023-27163) https://github.com/ThickCoco/CVE-2023-27163-POC POC详情
5 PoC CVE-2023-27163, SSRF, request-baskets hasta v1.2.1 https://github.com/davuXVI/CVE-2023-27163 POC详情
6 Requests Baskets (CVE-2023-27163) and Mailtrail v0.53 https://github.com/HusenjanDev/CVE-2023-27163-AND-Mailtrail-v0.53 POC详情
7 CVE-2023-27163 - Request Baskets SSRF https://github.com/rvizx/CVE-2023-27163 POC详情
8 Golang PoC for CVE-2023-27163 Mailtrail Exploit https://github.com/thomas-osgood/CVE-2023-27163 POC详情
9 CVE-2023-27163 Request-Baskets v1.2.1 - Server-side request forgery (SSRF) https://github.com/0xFTW/CVE-2023-27163 POC详情
10 A tool to perform port scanning using vulnerable Request-Baskets https://github.com/samh4cks/CVE-2023-27163-InternalProber POC详情
11 Python implementation of CVE-2023-27163 https://github.com/Hamibubu/CVE-2023-27163 POC详情
12 CVE-2023-27163 Request-Baskets v1.2.1 - Server-side request forgery (SSRF) https://github.com/cowsecurity/CVE-2023-27163 POC详情
13 this is a script that exploits the CVE-2023-27163 vulnerability which is request-basket SSRF https://github.com/KharimMchatta/basketcraft POC详情
14 Proof of Concept for Server Side Request Forgery (SSRF) in request-baskets (V<= v.1.2.1) https://github.com/MasterCode112/CVE-2023-27163 POC详情
15 Request Baskets vulnerable exploit to Server-Side Request Forgery up to version 1.2.1 https://github.com/mathias-mrsn/CVE-2023-27163 POC详情
16 A exploit for the CVE-2023-27163 (SSRF) vulnerability in the web application request-baskets (<= v.1.2.1) https://github.com/Rubioo02/CVE-2023-27163 POC详情
17 PoC for SSRF in request-baskets v1.2.1 (CVE-2023-27163) https://github.com/madhavmehndiratta/CVE-2023-27163 POC详情
18 It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU' machine from hackthebox https://github.com/Rishabh-Kumar-Cyber-Sec/CVE-2023-27163-ssrf-to-port-scanning POC详情
19 None https://github.com/btar1gan/exploit_CVE-2023-27163 POC详情
20 SSRF CVE-2023-27163 + maltrail vuln RCE https://github.com/G4sp4rCS/htb-sau-automated POC详情
21 Request Baskets is exposed. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/request-baskets-exposure.yaml POC详情
22 CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request. This POC utilizes the SSRF to perfrom RCE. https://github.com/lukehebe/CVE-2023-27163 POC详情
23 Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before. https://github.com/J0ey17/Exploit_CVE-2023-27163 POC详情
24 PoC and internal port brute-forcer for CVE-2023-27163 https://github.com/theopaid/CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer POC详情
25 Request-Baskets <= 1.2.1 allows unauthenticated SSRF via the forward_url parameter when creating a new basket. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27163.yaml POC详情
26 A exploit for the CVE-2023-27163 (SSRF) vulnerability in the web application request-baskets (<= v.1.2.1) https://github.com/apaz-dev/CVE-2023-27163 POC详情
27 CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request. This POC utilizes the SSRF to perfrom RCE. https://github.com/lukehebe/CVE-2023-27163-POC POC详情
28 Exploit for CVE-2023-27163 - SSRF Baskets Requests https://github.com/thealchimist86/CVE-2023-27163---SSRF-Baskets-Requests POC详情
29 Exploit for CVE-2023-27163 - Maltrail(0.53) - RCE https://github.com/thealchimist86/CVE-2023-27163---Maltrail-0.53---RCE POC详情
AI 生成 POC 已实测靶场 高级
已在真实靶场复现成功 · 下方是搭建环境并实际触发漏洞的真实录像。
成功标志: VULNERABLE: SSRF confirmed - request-baskets v1.2.1 forwarded request to internal http://target:8000/ and returned its secret body: PROOF_395fedaa755eeb4d
复现录像为 Pro+ 专属
观看本 CVE 的完整沙箱构建 + 真实利用录像。限时 ¥499/月。
升级 Pro+
claude_code · 2816 chars
Pro+ 专属包含:
漏洞复现靶场录像(真实沙箱构建 + 触发,独家)
漏洞原理深度分析
触发条件与影响面
完整可执行 POC 代码
利用链与缓解建议
POC 打包下载
每月 100+ 条 AI 生成额度

三、漏洞 CVE-2023-27163 的情报信息

请登录查看更多情报信息。

CVE-2023-27163 公开利用代码 (2)

CVE-2023-27163 其他参考 (4)

同批安全公告 · n/a · 2023-03-31 · 共 24 条

CVE-2023-1773 6.3 MEDIUM RockOA 代码注入漏洞
CVE-2023-1784 5.3 MEDIUM Jeecg-Boot 授权问题漏洞
CVE-2023-1772 3.5 LOW DataGear 跨站脚本漏洞
CVE-2023-29141 MediaWiki 安全漏洞
CVE-2023-29140 MediaWiki 安全漏洞
CVE-2023-29139 MediaWiki 安全漏洞
CVE-2023-29137 MediaWiki 安全漏洞
CVE-2023-28879 Artifex Software Ghostscript 缓冲区错误漏洞
CVE-2023-28877 VTEX apps-graphql 安全漏洞
CVE-2023-28862 LemonLDAP::NG 授权问题漏洞
CVE-2023-28464 Linux kernel 资源管理错误漏洞
CVE-2023-27162 openapi-generator 代码问题漏洞
CVE-2023-27160 forem 代码问题漏洞
CVE-2023-27159 Appwrite 代码问题漏洞
CVE-2023-26925 D-Link DIR-882 安全漏洞
CVE-2023-26858 PrestaSHp faqs SQL注入漏洞
CVE-2023-26830 Gladinet CentreStack 代码问题漏洞
CVE-2023-26829 Gladinet CentreStack 安全漏洞
CVE-2023-23594 SATO America CL4NX 安全漏洞
CVE-2022-4899 Zstandard 资源管理错误漏洞

显示前 20 条,共 24 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-27163

暂无评论


发表评论