Skip to content

Request Forgery in Multiple Integrations

Critical
shamoon published GHSA-24m5-7vjx-9x37 Jun 3, 2024

Package

homepage

Affected versions

< 0.9.1

Patched versions

0.9.1

Description

Summary

Several integrations are vulnerable to requests to unexpected APIs of the integrated services and retrieve their responses. This could lead to significant information disclosure, including credentials (like API keys or passwords), personal information, internal settings, etc., that could end up even in remote code execution.

Severity

Critical
10.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE ID

No known CVE

Credits