CVE-2023-41054

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Sep 4, 2023
Updated: Sep 8, 2023
CWE ID 918

Summary

CVE-2023-41054 is a Server-Side Request Forgery (SSRF) vulnerability affecting the LibreY meta search engine. Before commit 8f9b9803f231e2954e5b49987a532d28fe50a627, the `image_proxy.php` file contained the flaw. This issue allows remote attackers to leverage the server as a proxy to send HTTP GET requests to arbitrary targets, potentially gaining access to internal network information or conducting Denial-of-Service (DoS) attacks. The attacker can also request the server to download large files or chain requests among multiple instances to degrade server performance or even deny access from legitimate users. This vulnerability has been addressed in the latest commit available at <https://github.com/Ahwxorg/LibreY/pull/31>. LibreY hosts are strongly encouraged to update their instances to the latest commit as there are currently no known workarounds for this flaw.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share