GHSA-v6w6-358x-2433: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve exposes two admin node test endpoints under the Admin.Read OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for Admin.Read to trigger operational network actions that should require Admin.Write.
References
Code Behaviors & Features
Detect and mitigate GHSA-v6w6-358x-2433 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →