vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF)
50
Medium Risk
Adminer's ClickHouse driver treats the entire raw HTTP response body from the configured server as the connection error text and displays it without checking that the response actually came from a ClickHouse server. Because the login form lets a visitor supply the server address, this lets that visitor probe arbitrary internal hosts and read their HTTP response content back through the Adminer login error message. The fix limits the printed error to output ClickHouse itself reports as an error.
You are affected if you are using a version that falls within the vulnerable range and you have deployed Adminer with the optional ClickHouse driver enabled.
vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.0.0 - 6.0.1.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.