CVE-2019-9187

ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki:ikiwiki:3.20180105:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki:ikiwiki:3.20180228:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki:ikiwiki:3.20180311:*:*:*:*:*:*:*

History

21 Nov 2024, 04:51

Type Values Removed Values Added
References () https://ikiwiki.info/news/ - Vendor Advisory () https://ikiwiki.info/news/ - Vendor Advisory
References () https://ikiwiki.info/news/version_3.20190228/ - () https://ikiwiki.info/news/version_3.20190228/ -
References () https://lists.debian.org/debian-lts-announce/2019/03/msg00018.html - () https://lists.debian.org/debian-lts-announce/2019/03/msg00018.html -

Information

Published : 2019-06-05 18:29

Updated : 2024-11-21 04:51


NVD link : CVE-2019-9187

Mitre link : CVE-2019-9187

CVE.ORG link : CVE-2019-9187


JSON object : View

Products Affected

ikiwiki

  • ikiwiki
CWE
CWE-918

Server-Side Request Forgery (SSRF)