Server-Side Request Forgery in Baserow Web Application by Baserow Team
CVE-2021-22255
7.7HIGH
What is CVE-2021-22255?
A server-side request forgery (SSRF) vulnerability exists in versions of Baserow prior to 1.1.0. This flaw allows authenticated remote users to exploit the URL file upload functionality to retrieve files from the internal server network. By supplying an internal IP address, attackers can access sensitive data that should remain inaccessible, potentially leading to data exposure and breaches of internal security protocols.
Affected Version(s)
Baserow >0.6.0, <1.1.0
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [CaptainFreak](https://github.com/CaptainFreak) for reporting this vulnerability and for advising how to fix it.
