
We found results for “”
CVE-2024-1063
Good to know:

Date: January 30, 2024
Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Server-Side Request Forgery (SSRF)
CWE-918Top Fix

Upgrade Version
Upgrade to version appwrite/server-ce - dev-feat-0-13-4-release;appwrite/server-ce - dev-dependabot/npm_and_yarn/ini-1.3.7;appwrite/server-ce - dev-chore-prepare-1-3-6;appwrite/server-ce - dev-base-0.9.5;appwrite/server-ce - dev-chore-1.4.x-upgrade;appwrite/server-ce - dev-chore-prepare-0-13-1;appwrite/server-ce - dev-feat-1.4.7-release-prep;appwrite/server-ce - dev-fix-0.7-docs;appwrite/server-ce - dev-feat-prepare-0-15-3;appwrite/server-ce - dev-0.11-acme-fix;appwrite/server-ce - dev-chore-sync-1-3-x;appwrite/server-ce - dev-1.4.13+15;appwrite/server-ce - dev-feat-release-0-12-1;appwrite/server-ce - dev-feat-changelog-0.9.1;appwrite/server-ce - dev-feat-0.7.1-release;appwrite/server-ce - dev-update-cli-1.2.1;appwrite/server-ce - dev-feat-changelog-0.9;appwrite/server-ce - dev-chore-update-0.12.2;appwrite/server-ce - dev-prepare-0-15-2;appwrite/server-ce - dev-chore-readme-0.12.3;appwrite/server-ce - dev-feat-prepare-1.0.1-release;appwrite/server-ce - 1.4.11+4;appwrite/server-ce - dev-1.2.x-fix-deps-version;appwrite/server-ce - dev-chore-prepare-1-0-3;appwrite/server-ce - dev-docs-0-15-1;appwrite/server-ce - dev-queue-0.8.1;appwrite/server-ce - dev-feat-update-db-to-0.6;appwrite/server-ce - dev-LauraDuRy-patch-1;appwrite/server-ce - dev-security-release-0.11.1;appwrite/server-ce - dev-0.16.shmuel.1;appwrite/server-ce - dev-0.12-acme-fix;appwrite/server-ce - dev-feat-1.4.6-release-prep;appwrite/server-ce - dev-chore-0-13-changelog;appwrite/server-ce - dev-chore-prepare-1-0-2;appwrite/server-ce - dev-chore-release-1-1-2;appwrite/server-ce - dev-feat-1.4.8-release-prep;appwrite/server-ce - dev-chore-prepare-1-1-1;appwrite/server-ce - dev-chore-prepare-0-13-3;appwrite/server-ce - dev-feat-0-15-response-filters;appwrite/server-ce - dev-feat-1.4.9-release-prep;appwrite/server-ce - dev-1.1.x-examples;appwrite/server-ce - dev-chore-prepare-1-3-1;appwrite/server-ce - dev-feat-1.4.5-release
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |