CVE-2022-23644 describes a Server-Side Request Forgery (SSRF) vulnerability in BookWyrm, a decentralized social network for tracking reading. This flaw allows a logged-in user to force the server to make requests to internal or external resources, potentially leading to information disclosure or further attacks. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low privileges and no user interaction, potentially impacting confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, administrators are urged to upgrade to BookWyrm version 0.3.0 or restrict user registration to trusted individuals as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.0CPE matchmatch criteria | cpe:2.3:a:joinbookwyrm:bookwyrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.