First published: Fri Sep 22 2023(Updated: )
Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version 22.05 contains a patch for this issue.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Galaxyproject Galaxy | <22.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42812 is a vulnerability in Galaxy, an open-source platform for FAIR data analysis.
The severity of CVE-2023-42812 is medium with a severity value of 4.3.
Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious user to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses.
Updating Galaxy to version 22.05 or newer will fix CVE-2023-42812, as it contains a patch for the vulnerability.
CWE-918 is a vulnerability classification category called 'Server-Side Request Forgery (SSRF).'