CVE-2021-32698
Summary
| CVE | CVE-2021-32698 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-21 22:15:00 UTC |
| Updated | 2021-06-28 20:45:00 UTC |
| Description | eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Blind Server-Side Request Forgery (SSRF) in eLabFTW · Advisory · elabftw/elabftw · GitHub | CONFIRM | github.com | |
| security: prevent blind ssrf in pdf generation · elabftw/elabftw@3d2db4d · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.