GHSL-2023-185: Server-Side Request Forgery (SSRF) in Posthog - CVE-2023-46746
Published Dec 1, 2023
·Updated
A server-side request forgery (SSRF), which can only be exploited by authenticated users, was found in Posthog.
Affected Software
1 affected component
PostHog PostHog
Event History
Dec 1, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-185?
The severity of GHSL-2023-185 is rated at 44, indicating a significant risk due to the server-side request forgery (SSRF) vulnerability.
2
Who can exploit GHSL-2023-185?
GHSL-2023-185 can only be exploited by authenticated users of PostHog.
3
How do I fix GHSL-2023-185?
To fix GHSL-2023-185, upgrade PostHog to version 1.43.1 or later.
4
What type of vulnerability is GHSL-2023-185?
GHSL-2023-185 is classified as a server-side request forgery (SSRF) vulnerability.
5
In which software is GHSL-2023-185 found?
GHSL-2023-185 is found in the PostHog software.