CVE-2023-45815: Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context
(updated )
Related issue & discussion:
- https://github.com/ArchiveBox/ArchiveBox/issues/239
- https://github.com/ArchiveBox/ArchiveBox/wiki/Security-Overview#publishing
- https://github.com/ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive#security-concerns
References
- en.wikipedia.org/wiki/Cross-site_request_forgery
- github.com/ArchiveBox/ArchiveBox
- github.com/ArchiveBox/ArchiveBox/commit/a6548df8d0aae1d3d326deb1191b128232708166
- github.com/ArchiveBox/ArchiveBox/issues/239
- github.com/ArchiveBox/ArchiveBox/pull/1773
- github.com/ArchiveBox/ArchiveBox/security/advisories/GHSA-cr45-98w9-gwqx
- github.com/ArchiveBox/ArchiveBox/wiki/Configuration
- github.com/ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive
- github.com/ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive
- github.com/ArchiveBox/ArchiveBox/wiki/Security-Overview
- github.com/advisories/GHSA-cr45-98w9-gwqx
- github.com/pypa/advisory-database/tree/main/vulns/archivebox/PYSEC-2023-229.yaml
- nvd.nist.gov/vuln/detail/CVE-2023-45815
Code Behaviors & Features
Detect and mitigate CVE-2023-45815 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →