imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Jan 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2. | |
Title | imgproxy is vulnerable to SSRF against 0.0.0.0 | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-27T17:23:58.303Z
Updated: 2025-02-12T20:41:35.745Z
Reserved: 2025-01-20T15:18:26.988Z
Link: CVE-2025-24354

No data.

Status : Received
Published: 2025-01-27T18:15:41.197
Modified: 2025-01-27T18:15:41.197
Link: CVE-2025-24354

No data.