CVE-2024-0403

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
01/03/2024
Last modified:
19/05/2025

Description

Recipes version 1.5.10 allows arbitrary HTTP requests to be made<br /> <br /> through the server. This is possible because the application is<br /> <br /> vulnerable to SSRF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tandoor:recipes:1.5.10:*:*:*:*:*:*:*