MEDIUM
Recipes 1.5.10 - Blind SSRF
Published Feb 29, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.43%
Description
Recipes version 1.5.10 allows arbitrary HTTP requests to be made
through the server. This is possible because the application is
vulnerable to SSRF.
Affected products
-
- Version 1.5.10StatusaffectedConstraints-
- Version
-
- Version 1.5.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Tandoorrecipes | Recipes | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://fluidattacks.com/advisories/harris/ ExploitVendor Advisory
- https://github.com/TandoorRecipes/recipes/ Product
| Link | Providers | Tags |
|---|---|---|
| https://fluidattacks.com/advisories/harris/ | ExploitVendor Advisory | |
| https://github.com/TandoorRecipes/recipes/ | Product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Feb 29, 2024
Updated May 19, 2025
Reserved Jan 10, 2024
Link CVE-2024-0403
CISA Vulnrichment
Updated Mar 5, 2024