CVE-2022-0767
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to localhost.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2022-0767, https://github.com/janeczku/calibre-web/commit/965352c8d96c9eae7a6867ff76b0db137d04b0b8, https://github.com/janeczku/calibre-web, https://huntr.dev/bounties/b26fc127-9b6a-4be7-a455-58aefbb62d9e, https://pypi.org/project/calibreweb, https://github.com/advisories/GHSA-h65g-jfqg-2w6m