Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40014
HistoryApr 01, 2023 - 7:50 a.m.

Server-side Request Forgery (SSRF)

2023-04-0107:50:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
server-side request forgery
vulnerability
lambdaisland:uri
authority-regex
malicious urls
untrusted source

EPSS

0.001

Percentile

36.2%

lambdaisland:uri is vulnerable to Server-side Request Forgery (SSRF). The vulnerability is due to the authority-regex which allows an attacker to send malicious URLs to be parsed without properly handling the backslash (\\) character in the host, allowing an attacker to parse an untrusted source.

EPSS

0.001

Percentile

36.2%