Vulnerability Description
An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getrebuild | Rebuild | 3.5.0 |
Related Weaknesses (CWE)
References
- http://rebuild.comNot Applicable
- https://deeply-capri-1c8.notion.site/REBUILD-V3-5-2023-12-11-SSRF-30324be04e0047Broken Link
- https://github.com/getrebuild/rebuild/Product
- http://rebuild.comNot Applicable
- https://deeply-capri-1c8.notion.site/REBUILD-V3-5-2023-12-11-SSRF-30324be04e0047Broken Link
- https://github.com/getrebuild/rebuild/Product
FAQ
What is CVE-2024-25294?
CVE-2024-25294 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.
How severe is CVE-2024-25294?
CVE-2024-25294 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-25294?
Check the references section above for vendor advisories and patch information. Affected products include: Getrebuild Rebuild.