PT-2026-85555 · Marqo Ai · Marqo
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Marqo 2.26.0 contains a server-side request forgery vulnerability in the add documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download image from url and fetch content sample functions which lack destination filtering and host validation to access internal services and cloud metadata endpoints.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Marqo