HIGH 8.6 npm
Strapi Server-Side Request Forgery (SSRF)
GHSA-p9ff-j98v-p435 · CVE-2024-37818
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request.
Ready to move
Start Securing
Free, no credit card | First findings in minutes