
Cloud Vulnerability DB
A community-led vulnerabilities database
A Server-Side Request Forgery (SSRF) vulnerability exists in mintplex-labs/anything-llm that allows attackers to bypass intranet IP address and protocol restrictions. The vulnerability is tracked as CVE-2024-4084 and was published on June 4, 2024 (NVD).
The vulnerability exists despite efforts to filter out intranet IP addresses starting with 192, 172, 10, and 127 through regular expressions and limit access protocols to HTTP and HTTPS. Attackers can bypass these restrictions using alternative representations of IP addresses and accessing other ports running on localhost. The CVSS v3.1 base score is 7.5 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (NVD).
This vulnerability enables attackers to access any asset on the internal network, attack web services on the internal network, scan hosts on the internal network, and potentially access AWS metadata endpoints. The vulnerability stems from insufficient validation of user-supplied URLs (NVD).
The vulnerability is actively exploitable and requires no user interaction or privileges to execute. Proof of concept exploits have been published demonstrating the bypass of security controls (huntr).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."