Lucene search

K
cve[email protected]CVE-2023-48711
HistoryNov 24, 2023 - 5:15 p.m.

CVE-2023-48711

2023-11-2417:15:07
CWE-918
web.nvd.nist.gov
9
cve-2023-48711
google-translate-api-browser
npm
ssrf
vulnerability
translateoptions
tld
security
upgrade
nvd

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the google-translate-api-browser package and exposing the translateOptions to the end user. An attacker can set a malicious tld, causing the application to return unsafe URLs pointing towards local resources. The translateOptions.tld field is not properly sanitized before being placed in the Google translate URL. This can allow an attacker with control over the translateOptions to set the tld to a payload such as @127.0.0.1. This causes the full URL to become https://[email protected]/..., where translate.google. is the username used to connect to localhost. An attacker can send requests within internal networks and the local host. Should any HTTPS application be present on the internal network with a vulnerability exploitable via a GET call, then it would be possible to exploit this using this vulnerability. This issue has been addressed in release version 4.1.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected configurations

Vulners
NVD
Node
cjvnjdegoogle_translate_api_browserRange<4.1.3
VendorProductVersionCPE
cjvnjdegoogle_translate_api_browser*cpe:2.3:a:cjvnjde:google_translate_api_browser:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "cjvnjde",
    "product": "google-translate-api-browser",
    "versions": [
      {
        "version": "< 4.1.3",
        "status": "affected"
      }
    ]
  }
]

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Related for CVE-2023-48711