CVE-2023-27160: SSRF
Published Mar 31, 2023
·Updated
forem up to v2022.11.11 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /articles/{id}. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
Affected Software
1 affected component
forem forem<=2022.11.11
Event History
Mar 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-27160?
CVE-2023-27160 is classified as a high severity vulnerability due to its potential for server-side request forgery (SSRF) attacks.
2
How do I fix CVE-2023-27160?
To fix CVE-2023-27160, upgrade Forem to a version later than 2022.11.11 where the vulnerability is addressed.
3
What type of vulnerability is CVE-2023-27160?
CVE-2023-27160 is a Server-Side Request Forgery (SSRF) vulnerability.
4
What can attackers do with CVE-2023-27160?
Attackers can exploit CVE-2023-27160 to access network resources and sensitive information through crafted POST requests.
5
Which versions of Forem are affected by CVE-2023-27160?
CVE-2023-27160 affects Forem versions up to and including 2022.11.11.