info: name: OneNav v0.9.35-20240318- Server-Side Request Forgery (SSRF) author: ritikchaddha severity: medium description: | OneNav v0.9.35-20240318 is vulnerable to server-side request forgery (SSRF) via the url parameter in the get_link_info API. An attacker can force the server to make arbitrary requests, potentially accessing internal resources. reference: - https://github.com/Hebing123/cve/issues/39 - https://nvd.nist.gov/vuln/detail/CVE-2024-33832 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L cvss-score:6.5 cve-id: CVE-2024-33832 cwe-id: CWE-918 metadata: max-request:2 product: onenav fofa-query: title="onenav" shodan-query: title:"onenav" tags: cve,cve2024,ssrf,onenav,oast,authenticated