Skip to content

Blind SSRF in `podcastUtils.js` (`GHSL-2023-267`)

Low
advplyr published GHSA-jhjx-c3wx-q2x7 Dec 23, 2023

Package

audiobookshelf

Affected versions

2.6.0

Patched versions

2.7.0

Description

Summary

Audiobookshelf v2.6.0 is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in podcastUtils.js.

Severity

Low

CVE ID

CVE-2023-51697

Weaknesses

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Learn more on MITRE.

Credits