CVE-2019-9187: SSRF
Published Jun 5, 2019
·Updated
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
Affected Software
5 affected components
Ikiwiki ikiwiki<3.20170111.1
Ikiwiki ikiwiki>=3.20190207<3.20190226
Ikiwiki ikiwiki=3.20180105
Ikiwiki ikiwiki=3.20180228
Ikiwiki ikiwiki=3.20180311
Event History
Jun 5, 2019
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-9187?
CVE-2019-9187 is classified as a moderate severity vulnerability due to its potential for SSRF and local file reading.
2
How do I fix CVE-2019-9187?
To fix CVE-2019-9187, upgrade to Ikiwiki version 3.20190228 or later.
3
What type of vulnerability is CVE-2019-9187?
CVE-2019-9187 is an SSRF vulnerability that also allows reading local files through file: URIs.
4
Which Ikiwiki versions are affected by CVE-2019-9187?
CVE-2019-9187 affects Ikiwiki versions before 3.20170111.1 and between 3.20190207 and 3.20190226, among others.
5
What is the impact of CVE-2019-9187?
The impact of CVE-2019-9187 includes the potential for unauthorized access to local files and exploitation through SSRF.