7.5
CVSSv3

CVE-2019-9187

Published: 05/06/2019 Updated: 17/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ikiwiki prior to 3.20170111.1 and 3.2018x and 3.2019x prior to 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ikiwiki ikiwiki 3.20180228

ikiwiki ikiwiki 3.20180105

ikiwiki ikiwiki

ikiwiki ikiwiki 3.20180311

Vendor Advisories

Joey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service For the stable distribution (stretch), this problem has been fixed in version 3201701111 We recommend that you upgrade your ikiwiki packages For the detailed securi ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> ikiwiki: CVE-2019-9187: Server-side request forgery <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Simon McVitti ...