Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 76% de las CVE
explotación observada
noninguna fuente lo reporta
Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
triggerdotdev · trigger.devReferencias
https://github.com/triggerdotdev/trigger.devhttps://github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254https://github.com/triggerdotdev/trigger.dev/issues/4172https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-xxv7-2vv3-h682https://www.vulncheck.com/advisories/trigger-dev-before-4.5.2-server-side-request-forgery-via-webhook-alert-channel