First published: Wed Jun 05 2019(Updated: )
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ikiwiki Hosting Project | <3.20170111.1 | |
Ikiwiki Hosting Project | >=3.20190207<3.20190226 | |
Ikiwiki Hosting Project | =3.20180105 | |
Ikiwiki Hosting Project | =3.20180228 | |
Ikiwiki Hosting Project | =3.20180311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9187 is classified as a moderate severity vulnerability due to its potential for SSRF and local file reading.
To fix CVE-2019-9187, upgrade to Ikiwiki version 3.20190228 or later.
CVE-2019-9187 is an SSRF vulnerability that also allows reading local files through file: URIs.
CVE-2019-9187 affects Ikiwiki versions before 3.20170111.1 and between 3.20190207 and 3.20190226, among others.
The impact of CVE-2019-9187 includes the potential for unauthorized access to local files and exploitation through SSRF.