CVE-2022-42149: SSRF
Published Oct 17, 2022
·Updated
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
Affected Software
1 affected component
keking kkFileView=4.0.0
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42149?
CVE-2022-42149 is a vulnerability in kkFileView 4.0 that allows for Server-side request forgery (SSRF) attacks.
2
What is the severity level of CVE-2022-42149?
CVE-2022-42149 severity level is critical with a score of 9.8.
3
How does CVE-2022-42149 impact kkFileView 4.0?
CVE-2022-42149 allows attackers to perform Server-side request forgery (SSRF) attacks in kkFileView 4.0.
4
Is there a fix available for CVE-2022-42149?
A fix for CVE-2022-42149 is not available at the moment. It is recommended to follow the vendor's advisory for any updates or patches.
5
Where can I find more information about CVE-2022-42149?
You can find more information about CVE-2022-42149 at the following link: https://github.com/xiaojiangxl/paper/blob/main/kkFileView/ssrf_vul_en.md