Lucene search

K
osvGoogleOSV:CVE-2022-23644
HistoryFeb 16, 2022 - 7:15 p.m.

CVE-2022-23644

2022-02-1619:15:00
Google
osv.dev
6
bookwyrm
decentralized social network
ssrf
vulnerability
patched
v0.3.0
security
upgrade
workaround
registration
trusted individuals
server-side request forgery

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

42.8%

BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a logged-in user. The problem has been patched and administrators should upgrade to version 0.3.0 As a workaround, BookWyrm instances can close registration and limit members to trusted individuals.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for OSV:CVE-2022-23644