CVE-2024-0403

Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tandoor:recipes:1.5.10:*:*:*:*:*:*:*

History

31 Dec 2024, 17:35

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/harris/ - () https://fluidattacks.com/advisories/harris/ - Exploit, Vendor Advisory
References () https://github.com/TandoorRecipes/recipes/ - () https://github.com/TandoorRecipes/recipes/ - Product
CPE cpe:2.3:a:tandoor:recipes:1.5.10:*:*:*:*:*:*:*
First Time Tandoor
Tandoor recipes

21 Nov 2024, 08:46

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/harris/ - () https://fluidattacks.com/advisories/harris/ -
References () https://github.com/TandoorRecipes/recipes/ - () https://github.com/TandoorRecipes/recipes/ -

01 Mar 2024, 14:04

Type Values Removed Values Added
Summary
  • (es) La versión 1.5.10 de Recipes permite realizar solicitudes HTTP arbitrarias a través del servidor. Esto es posible porque la aplicación es vulnerable a SSRF.

01 Mar 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-01 00:15

Updated : 2024-12-31 17:35


NVD link : CVE-2024-0403

Mitre link : CVE-2024-0403

CVE.ORG link : CVE-2024-0403


JSON object : View

Products Affected

tandoor

  • recipes
CWE
CWE-918

Server-Side Request Forgery (SSRF)