CVE-2021-39195: Server-Side Request Forgery vulnerability in misskey
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal network. This has been fixed in 12.90.0. However, if you are using a proxy, you will need to take additional measures. As a workaround this exploit may be avoided by appropriately restricting access to private networks from the host where the application is running.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
misskeyto a version that resolves this vulnerability.Fixed in 12.90.0 - Compensating control
As a workaround, restrict access to private networks from the host where the Misskey application is running to avoid the SSRF conditions.
- Compensating control
If using a proxy with Misskey, take additional measures (per proxy configuration) to prevent SSRF from reaching private/internal networks.
Event History
Frequently Asked Questions
What is CVE-2021-39195?
CVE-2021-39195 is a Server-Side Request Forgery vulnerability found in the Misskey microblogging platform.
What is the severity of CVE-2021-39195?
CVE-2021-39195 has a severity rating of 6.5, which is considered high.
How does CVE-2021-39195 affect Misskey?
CVE-2021-39195 affects Misskey versions up to 12.90.0.
What is the risk of CVE-2021-39195?
CVE-2021-39195 could lead to the disclosure of non-public information within the internal network.
How can CVE-2021-39195 be fixed?
To fix CVE-2021-39195, users should update to the latest version of Misskey.