UBUNTU-CVE-2019-11767

Source
https://ubuntu.com/security/CVE-2019-11767
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11767.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-11767
Related
Published
2019-05-05T06:29:00Z
Modified
2024-10-15T14:06:50Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.

References

Affected packages

Ubuntu:Pro:14.04:LTS / phpbb3

Package

Name
phpbb3
Purl
pkg:deb/ubuntu/phpbb3?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.11-5
3.0.12-1
3.0.12-1ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / phpbb3

Package

Name
phpbb3
Purl
pkg:deb/ubuntu/phpbb3?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.14-1
3.0.14-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}