First published: Thu Sep 02 2021(Updated: )
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Bookstackapp Bookstack | <21.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-3758.
The severity of CVE-2021-3758 is medium with a CVSS score of 6.5.
The affected software for CVE-2021-3758 is bookstack version up to and excluding 21.08.
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to send crafted requests from the vulnerable server to other internal or external resources.
Yes, you can find references for CVE-2021-3758 at the following links: [GitHub Commit](https://github.com/bookstackapp/bookstack/commit/bee5e2c7ca637d034c6985c0328cef0ce068778e), [Huntr Bounty](https://huntr.dev/bounties/a8d7fb24-9a69-42f3-990a-2db93b53f76b).