First published: Mon Nov 20 2023(Updated: )
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bookstackapp Bookstack | =23.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-6199.
The severity of CVE-2023-6199 is high.
The affected software is Book Stack version 23.10.2.
The vulnerability is caused by filtering local files on the server, which is possible due to the application being vulnerable to SSRF (Server-Side Request Forgery).
Yes, patches are available to fix this vulnerability. It is recommended to update to Book Stack version 23.10.3 or newer to mitigate the risk.