OneNav v0.9.35-20240318 is vulnerable to server-side request forgery (SSRF) via the url parameter in the get_link_info API. An attacker can force the server to make arbitrary requests, potentially accessing internal resources.
id: CVE-2024-33832
info:
name: OneNav v0.9.35-20240318 - Server-Side Request Forgery (SSRF)
aut
...