CVE-2023-30019: SSRF
imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
Other sources
imgproxy prior to version 3.15.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30019?
The severity of CVE-2023-30019 is high due to its potential for Server-Side Request Forgery (SSRF), allowing attackers to manipulate server-side requests.
How do I fix CVE-2023-30019?
To fix CVE-2023-30019, upgrade imgproxy to version 3.15.0 or later.
What versions of imgproxy are affected by CVE-2023-30019?
Versions of imgproxy prior to 3.15.0, specifically up to and including 3.14.0, are affected by CVE-2023-30019.
What type of vulnerability is CVE-2023-30019?
CVE-2023-30019 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Who is the vendor for CVE-2023-30019?
The vendor for CVE-2023-30019 is Evil Martians, responsible for maintaining the imgproxy software.