calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for 0.0.0.0
, which would result in a payload of 0.0.0.0
resolving to localhost
.
もっと詳しく