CVE-2024-28435: SSRF
Published Mar 25, 2024
·Updated
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
Affected Software
2 affected components
Twenty Twenty
Twenty Twenty=0.3.0
Event History
Mar 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28435?
CVE-2024-28435 has a moderate severity, as it allows for server-side request forgery through file upload.
2
How do I fix CVE-2024-28435?
Fix CVE-2024-28435 by upgrading the Twenty platform to a version that addresses this SSRF vulnerability.
3
What versions of the Twenty platform are affected by CVE-2024-28435?
CVE-2024-28435 affects Twenty version 0.3.0 specifically.
4
What types of attacks can CVE-2024-28435 enable?
CVE-2024-28435 can enable an attacker to perform internal network scans and other malicious actions via SSRF.
5
Is there a workaround for CVE-2024-28435 until I can update?
A temporary workaround for CVE-2024-28435 is to restrict file upload functionalities until the vulnerability is patched.