CVE-2024-46413: SSRF
Published Aug 25, 2025
·Updated
Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.
Affected Software
2 affected components
REBUILD REBUILD
getrebuild rebuild<=3.7.7
Event History
Aug 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-46413?
CVE-2024-46413 is classified as a medium severity vulnerability due to its potential for Server-Side Request Forgery (SSRF) attacks.
2
How do I fix CVE-2024-46413?
To mitigate CVE-2024-46413, update Rebuild to version 3.7.8 or later where the SSRF vulnerability has been addressed.
3
What systems are affected by CVE-2024-46413?
CVE-2024-46413 affects Rebuild versions up to and including 3.7.7.
4
What type of vulnerability is CVE-2024-46413?
CVE-2024-46413 is a Server-Side Request Forgery (SSRF) vulnerability.
5
What impact does CVE-2024-46413 have on systems?
CVE-2024-46413 can allow an attacker to make unauthorized requests on behalf of the server, potentially leading to data exposure.