CVE-2025-44594: SSRF
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44594?
CVE-2025-44594 is classified as a high severity vulnerability due to its potential to allow unauthorized access to internal services.
How do I fix CVE-2025-44594?
To resolve CVE-2025-44594, upgrade Halo to version 2.20.18 or later, which includes the necessary security patches.
What impact does CVE-2025-44594 have on my system?
CVE-2025-44594 can lead to server-side request forgery (SSRF), enabling attackers to make requests on behalf of the server to internal services.
Is my version of Halo affected by CVE-2025-44594?
Halo versions 2.20.17 and earlier are affected by CVE-2025-44594, so you should check your current version.
What is server-side request forgery (SSRF) as it relates to CVE-2025-44594?
In the context of CVE-2025-44594, SSRF refers to an attack where an attacker can trick the server into making illegitimate requests to internal resources.