Vulnerabilities > CVE-2022-22702 - Server-Side Request Forgery (SSRF) vulnerability in Partkeepr

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
partkeepr
CWE-918

Summary

PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.

Vulnerable Configurations

Part Description Count
Application
Partkeepr
1

Common Weakness Enumeration (CWE)