Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Lemmy: SSRF in /api/v3/post via Webmention dispatch
Vulnerability Description
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link post through POST /api/v3/post. When a post is created in a public community, the backend asynchronously sends a Webmention to the attacker-controlled link target. The submitted URL is checked for syntax and scheme, but the audited code path does not reject loopback, private, or link-local destinations before the Webmention request is issued. This lets a normal user trigger server-side HTTP requests toward internal services. This issue has been patched in version 0.19.18.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Lemmy 代码问题漏洞
Vulnerability Description
Lemmy是Lemmy开源的一款用于构建社交新闻聚合器和网络论坛的自由软件。 Lemmy 0.19.18之前版本存在代码问题漏洞,该漏洞源于创建链接帖子时未拒绝回环、私有或链路本地目标,可能导致服务端请求伪造。
CVSS Information
N/A
Vulnerability Type
N/A