漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url
Vulnerability Description
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend RPC method :create-file-media-object-from-url in backend/src/app/rpc/commands/media.clj, where media/download-image in backend/src/app/media.clj used the shared HTTP client without destination filtering, allowing an authenticated file editor to reach internal-only endpoints. This issue is fixed in version 2.15.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Penpot 服务端请求伪造漏洞
Vulnerability Description
penpot penpot是penpot公司开源的一款开源的设计和原型制作平台。 Penpot 2.15.0之前版本存在服务端请求伪造漏洞,该漏洞源于远程图片导入功能将用户控制的URL传递给后端RPC方法,且共享HTTP客户端未进行目标过滤,允许经过身份验证的文件编辑器访问内部端点。
CVSS Information
N/A
Vulnerability Type
N/A