You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/OpenAPITools/openapi-generator
packages:
- package: n/a
description: |
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
cves:
- CVE-2023-27162
references:
- web: http://openapi-generator.com
- web: https://github.com/OpenAPITools/openapi-generator
- web: https://notes.sjtu.edu.cn/s/2_yki_2Xq
- web: https://gist.github.com/b33t1e/6121210ebd9efd4f693c73b830d8ab08
The text was updated successfully, but these errors were encountered:
CVE-2023-27162 references github.com/OpenAPITools/openapi-generator, which may be a Go module.
Description:
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: