Vulnerabilities/

Strapi Server-Side Request Forgery (SSRF)

Severity:
High

Description

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@strapi/strapi
Anything's wrong? Let us know Last updated on October 04, 2024

This issue is available in SmartScanner Professional

See Pricing