CVE-2022-23071 is a Server-Side Request Forgery (SSRF) vulnerability affecting Tandoor Recipes versions 0.9.1 through 1.2.5. A low-privileged attacker can exploit the "Import Recipe" function by providing a localhost URL to access and read internal file system data, potentially exposing sensitive information. Rated Medium (CVSS 6.5), this vulnerability requires no user interaction and has high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.1, <= 1.2.5CPE matchmatch criteria | cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.