GHSA-4w8p-x6g8-fv64
Dashboard / Vulnerabilities / GHSA-4w8p-x6g8-fv64
GHSA-4w8p-x6g8-fv64
Summary: Server-Side Request Forgery in calibreweb
Details: calibreweb prior to version 0.6.16 contains a Server-Side Request Forgery (SSRF) vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-0339, https://github.com/janeczku/calibre-web/commit/35f6f4c727c887f8f3607fe3233dbc1980d15020, https://github.com/janeczku/calibre-web/commit/3b216bfa07ec7992eff03e55d61732af6df9bb92, https://github.com/janeczku/calibre-web, https://github.com/janeczku/calibre-web/releases/tag/0.6.16, https://github.com/pypa/advisory-database/tree/main/vulns/calibreweb/PYSEC-2022-23.yaml, https://huntr.dev/bounties/499688c4-6ac4-4047-a868-7922c3eab369
Affected packages
Package
Name: calibreweb
Purl: pkg:pypi/calibreweb
Affected ranges
Type: ECOSYSTEM
Events:
