Description
A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected products
- Akana / Akana API Platform2022.1.1 – 2022.1.1 (CVE-2024-2796 Patch)
- Akana / Akana API Platform2022.1.2 – 2022.1.2 (CVE-2024-2796 Patch)
- Akana / Akana API Platform0.0.0 – 2024.1.0
- Akana / Akana API Platform0.0.0 – 2022.1.3.2