Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.
History

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Tandoorrecipes
Tandoorrecipes recipes
CPEs cpe:2.3:a:tandoorrecipes:recipes:1.5.10:*:*:*:*:*:*:*
Vendors & Products Tandoorrecipes
Tandoorrecipes recipes
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 15:00:00 +0000

Type Values Removed Values Added
Description Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF. Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Tue, 31 Dec 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Tandoor
Tandoor recipes
CPEs cpe:2.3:a:tandoor:recipes:1.5.10:*:*:*:*:*:*:*
Vendors & Products Tandoor
Tandoor recipes

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2024-02-29T23:31:15.060Z

Updated: 2025-05-19T14:55:16.551Z

Reserved: 2024-01-10T16:40:59.115Z

Link: CVE-2024-0403

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.693Z

cve-icon NVD

Status : Modified

Published: 2024-03-01T00:15:51.850

Modified: 2025-05-19T15:15:21.730

Link: CVE-2024-0403

cve-icon Redhat

No data.