breakandpray.com
https://breakandpray.com/cve-2023-30019-ssrf-in-imgproxy CVE-2023-30019
MEDIUMNuclei
imgproxy is vulnerable to Server-Side Request Forgery
Record summary
CVE-2023-30019 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/imgproxy/imgproxy/v3Browse Go / github.com/imgproxy/imgproxy/v3 | GitHub Advisory | Before 3.15.0 · Fixed in 3.15.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMImgproxy <= 3.14.0 - Server-side request forgery (SSRF)CVSS 5.3
imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.
Remediation
Upgrade to a version of Imgproxy that is not affected by this vulnerability.
WeaknessesCWE-918
AuthorsDhiyaneshDK
Template tagscvecve2023imgproxyssrfoastevilmartiansvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:evilmartians:imgproxy:*:*:*:*:*:*:*:*
Shodan: Server: imgproxy
Shodan: server: imgproxy
https://breakandpray.com/cve-2023-30019-ssrf-in-imgproxy/ https://github.com/imgproxy/imgproxy https://github.com/j4k0m/godkiller
Source: ProjectDiscovery
References
5github.com
https://github.com/imgproxy/imgproxy github.com
https://github.com/imgproxy/imgproxy/blob/ee9e8f0cb101ec22318caffd552a23cc0548d5ce/imagedata/download.go github.com
https://github.com/imgproxy/imgproxy/commit/1a9768a2c682e88820064aa3d9a05ea234ff3cc4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-30019