CVE-2024-55089: SSRF
Published Dec 18, 2024
·Updated
Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.
Affected Software
2 affected components
Rhymix Rhymix
Rhymix Rhymix=2.1.19
Event History
Dec 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55089?
CVE-2024-55089 has a moderate severity level due to its potential for Server-Side Request Forgery (SSRF) exploits.
2
How do I fix CVE-2024-55089?
To fix CVE-2024-55089, upgrade to the latest version of Rhymix where the vulnerability is patched.
3
What type of vulnerability is CVE-2024-55089?
CVE-2024-55089 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
4
What software is affected by CVE-2024-55089?
CVE-2024-55089 affects Rhymix version 2.1.19.
5
What can an attacker achieve with CVE-2024-55089?
An attacker can exploit CVE-2024-55089 to make unauthorized requests from the server, potentially leading to data leakage or further attacks.