vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF)
58
Medium Risk
Adminer's Elasticsearch driver reads the raw HTTP response body returned when opening a connection and surfaces its error field verbatim as the connection error shown to the user, regardless of whether the response actually came from an Elasticsearch node. Combined with the login form's user-supplied server address, this lets a visitor probe arbitrary internal hosts and read their HTTP response content back through the Adminer login error message. The fix restricts the printed error to output Elasticsearch itself identifies as its own error payload.
You are affected if you are using a version that falls within the vulnerable range and you have deployed Adminer with the optional Elasticsearch driver enabled.
vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF) in versions 4.16.0 - 6.0.1.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.