CVE-2023-24060

MEDIUM

Haven 5d15944 - Authenticated Server-Side Request Forgery via Feed URL Parameter

Title source: llm
STIX 2.1

Description

Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RSS Feeds or add RSS Feeds can supply an arbitrary hostname (or even the hostname of the Haven server itself). NOTE: this product has significant usage but does not have numbered releases; ordinary end users may typically use the master branch.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/havenweb/haven/issues/51
Product, Vendor Advisory
https://havenweb.org/

Scores

CVSS v3 5.0
EPSS 0.0048
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
havenweb/haven 5d15944
Published Jan 27, 2023
Tracked Since Feb 18, 2026