CVE-2023-27159: SSRF
Published Mar 31, 2023
·Updated
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Affected Software
1 affected component
Appwrite Appwrite<=1.2.1
Event History
Mar 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-27159?
CVE-2023-27159 is considered a high severity vulnerability due to its potential for Server-Side Request Forgery.
2
How do I fix CVE-2023-27159?
To fix CVE-2023-27159, upgrade to Appwrite version 1.2.2 or later.
3
What components are affected by CVE-2023-27159?
CVE-2023-27159 affects the Appwrite software specifically in versions up to and including 1.2.1.
4
What type of vulnerability is CVE-2023-27159?
CVE-2023-27159 is a Server-Side Request Forgery (SSRF) vulnerability.
5
What can attackers do with CVE-2023-27159?
Attackers can exploit CVE-2023-27159 to access sensitive network resources and information via crafted GET requests.