Executive brief
Vrite is an open-source collaborative editor and content management platform. A Server-Side Request Forgery vulnerability allows attackers to make unauthorized requests from the server to internal or external systems, potentially exposing sensitive data or enabling lateral movement within a network.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Vrite SDK (@vrite/sdk) prior to version 0.3.0, classified as CWE-918. The vulnerability allows unauthenticated attackers with network access to craft malicious requests that the Vrite server will execute on their behalf. This enables attackers to access internal services, bypass firewall restrictions, read local files, or interact with internal APIs. The vulnerability was patched in version 0.3.0, released on October 10, 2023.
Affected products
- Vrite Vrite prior to 0.3.0
Timeline
- 2023-10-13: disclosed
- 2023-10-10: patched