Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function
Vulnerability Description
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the fetchTitleAndHeaders function allows authenticated users to make arbitrary HTTP requests to internal services due to insufficient URL validation that only checks for "http://" or "https://" prefixes. This issue has been patched in version 2.13.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Linkwarden 代码问题漏洞
Vulnerability Description
Linkwarden是Linkwarden开源的一个自托管协作书签管理器。 Linkwarden 2.13.0之前版本存在代码问题漏洞,该漏洞源于fetchTitleAndHeaders函数中URL验证不足仅检查http://或https://前缀,可能导致认证用户对内部服务发起任意HTTP请求。
CVSS Information
N/A
Vulnerability Type
N/A