You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Check this link for more information on SSRF
Check this link for more information on how to fix this. Basically you would need to make sure only http and https URLs are accepted, and requests to non public ip addresses are blocked.
System Information
PartKeepr Version: Latest commit
The text was updated successfully, but these errors were encountered:
Considering #1059 you will probably not get a response or official recognition.
Which is terrible. The PartKeepr demo online looks like it was incredibly well thought out and works nicely, I guess just keeping it air-gapped and using it as-is might be sufficient for some. But dang, for a free self-hosted open source inventory management software, it's surprisingly good.
Bug description
Since there is no security policy and I cannot find contact information to the developers, I have to use issue to report this.
There is an SSRF vulnerability in PartKeeper. The add attatchment through URL function does not have any restriction on the URL.
Steps to reproduce
Suggestion
Check this link for more information on SSRF
Check this link for more information on how to fix this. Basically you would need to make sure only http and https URLs are accepted, and requests to non public ip addresses are blocked.
System Information
The text was updated successfully, but these errors were encountered: