MEDIUM
Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivoting requests through the server
Published Jul 23, 2018
4.9
MEDIUMCVSS 3.0
EPSS 0.97%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.