PT-2023-23999 · Pydio · Pydio Cells

CVE-2023-32750

·

Published

2023-06-03

·

Updated

2025-01-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pydio Cells versions 4.1.2 and earlier
Description The issue allows for Server-Side Request Forgery (SSRF) in Pydio Cells. This is possible through the creation of jobs that run in the background, specifically the "remote-download" job. This job can cause the backend to send an HTTP GET request to a specified URL and save the response to a new file, which is then available in a user-specified folder.
Recommendations For versions 4.1.2 and earlier, consider disabling the "remote-download" job as a temporary workaround until a patch is available. Restrict access to the job creation feature to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32750

Affected Products

Pydio Cells