CVE-2023-46746: GHSL-2023-185: Server-Side Request Forgery (SSRF) in Posthog - CVE-2023-46746
Published Dec 1, 2023
·Updated
A server-side request forgery (SSRF), which can only be exploited by authenticated users, was found in Posthog.
Affected Software
1 affected component
PostHog PostHog<=1.43.1
Remediation
Event History
Dec 1, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
CVE Published
via MITRE·09:53 PM
Data Sourced
via MITRE·09:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-46746.
2
What is the severity of CVE-2023-46746?
The severity of CVE-2023-46746 is medium (4.8).
3
Who is affected by CVE-2023-46746?
Posthog users with versions up to and including 1.43.1 are affected by CVE-2023-46746.
4
What is the impact of CVE-2023-46746?
Authenticated users of Posthog are vulnerable to server-side request forgery (SSRF) attacks.
5
How can CVE-2023-46746 be fixed?
To fix CVE-2023-46746, users should update to a version of Posthog that is not affected by the vulnerability.