A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerability is present in the crawl endpoint where the 'url' parameter can be manipulated to send HTTP requests to arbitrary URLs, thereby facilitating SSRF attacks. The affected code is located in the backend/routes/crawl_routes.py file, specifically within the crawl_endpoint function. This issue could allow attackers to interact with internal services that are accessible from the server hosting the application.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-06T18:39:58.505Z

Updated: 2024-06-06T18:39:58.505Z

Reserved: 2024-05-13T21:25:46.851Z


Link: CVE-2024-4851

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-06T19:16:02.800

Modified: 2024-06-07T14:56:05.647


Link: CVE-2024-4851

JSON object: View

cve-icon Redhat Information

No data.

CWE