github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/rudloff/alltube/CVE-2022-0768.yaml CVE-2022-0768
CRITICAL
Server-Side Request Forgery (SSRF) in rudloff/alltube
Record summary
CVE-2022-0768 has a selected CVSS score of 9.1 (critical).
Description
Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
rudloff/alltubeBrowse rudloff / rudloff/alltube | CVE List | Before 3.0.2 | affected |
rudloff/alltubeBrowse Packagist / rudloff/alltube | GitHub Advisory | Before 3.0.2 · Fixed in 3.0.2 | affected |
References
7github.com
https://github.com/Rudloff/alltube github.com
https://github.com/Rudloff/alltube/commit/3a4f09dda0a466662a4e52cde674749e0c668e8d github.com
https://github.com/Rudloff/alltube/security/advisories/GHSA-r5hc-wm3g-hjw6 github.com
https://github.com/rudloff/alltube/commit/148a171b240e7ceb076b9e198bef412de14ac55d huntr.devConfirmation
https://huntr.dev/bounties/9b14cc46-ec08-4940-83cc-9f986b2a5903 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0768