Record summary

CVE-2023-30019 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

github.com/imgproxy/imgproxy/v3

Browse Go / github.com/imgproxy/imgproxy/v3
GitHub AdvisoryBefore 3.15.0 · Fixed in 3.15.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMImgproxy <= 3.14.0 - Server-side request forgery (SSRF)CVSS 5.3

imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.

Remediation

Upgrade to a version of Imgproxy that is not affected by this vulnerability.

WeaknessesCWE-918
AuthorsDhiyaneshDK
Template tagscvecve2023imgproxyssrfoastevilmartiansvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:evilmartians:imgproxy:*:*:*:*:*:*:*:*
Shodan: Server: imgproxy
Shodan: server: imgproxy

Source: ProjectDiscovery

References

5