x/vulndb: potential Go vuln in github.com/imgproxy/imgproxy: CVE-2023-30019 #1761
Labels
excluded: NOT_IMPORTABLE
This vulnerability only exists in a binary and is not importable.
CVE-2023-30019 references github.com/imgproxy/imgproxy, which may be a Go module.
Description:
imgproxy <= 3.6.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: