CVE-2024-5885: Server-Side Request Forgery (SSRF) in stangirard/quivr
stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a malicious user to gain access to internal servers, the AWS metadata endpoint, and capture Supabase data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
stangirard/quivrto a version that resolves this vulnerability.Fixed in 0.0.236
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5885?
CVE-2024-5885 is classified as a medium severity vulnerability due to its ability to facilitate unauthorized access to local network applications.
How do I fix CVE-2024-5885?
To fix CVE-2024-5885, update to the latest version of Quivr where the SSRF vulnerability has been addressed.
What types of attacks can be performed using CVE-2024-5885?
CVE-2024-5885 can be exploited for Server-Side Request Forgery attacks, allowing attackers to interact with internal systems on the local network.
Which version of Quivr is affected by CVE-2024-5885?
CVE-2024-5885 specifically affects Quivr version 0.0.236.
How can I identify if CVE-2024-5885 is being exploited in my environment?
Monitor your application logs and network traffic for unusual requests or access patterns indicative of SSRF exploitation related to CVE-2024-5885.