CVE-2023-41054

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Sep 4, 2023
Updated: Sep 8, 2023
CWE ID 918

Summary

CVE-2023-41054 is a Server-Side Request Forgery (SSRF) vulnerability affecting the LibreY meta search engine. Before commit 8f9b9803f231e2954e5b49987a532d28fe50a627, the `image_proxy.php` file contained the flaw. This issue allows remote attackers to leverage the server as a proxy to send HTTP GET requests to arbitrary targets, potentially gaining access to internal network information or conducting Denial-of-Service (DoS) attacks. The attacker can also request the server to download large files or chain requests among multiple instances to degrade server performance or even deny access from legitimate users. This vulnerability has been addressed in the latest commit available at <https://github.com/Ahwxorg/LibreY/pull/31>. LibreY hosts are strongly encouraged to update their instances to the latest commit as there are currently no known workarounds for this flaw.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-41054 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions