CVE-2021-22255: SSRF
Published Aug 20, 2021
·Updated
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.
Affected Software
1 affected component
Baserow Baserow>=0.6.0<1.1.0
Remediation
Patch Available
Event History
Aug 20, 2021
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22255?
CVE-2021-22255 has a high severity score of 7.7 according to CVSS 3.1.
2
How do I fix CVE-2021-22255?
You can fix CVE-2021-22255 by applying the latest patch available for Baserow.
3
What is the risk associated with CVE-2021-22255?
CVE-2021-22255 poses a risk score of 44, indicating significant potential impact.
4
What does CVE-2021-22255 exploit?
CVE-2021-22255 exploits a Server-Side Request Forgery (SSRF) vulnerability in URL file uploads.
5
Who is affected by CVE-2021-22255?
CVE-2021-22255 affects remote authenticated users of Baserow versions prior to 1.1.0.