Beveiligingsadvies

CVE-2023-42812

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-09-22 16:07:02
Laatst bijgewerkt 2024-09-24 14:25:37
Toegewezen door GitHub_M
CVSS-score 6.3
Status PUBLISHED

Beschrijving

Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version 22.05 contains a patch for this issue.