{"id":"CVE-2023-42812","summary":"Galaxy vulnerable to Server Side Request Forgery during data imports","details":"Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version 22.05 contains a patch for this issue.","aliases":["GHSA-vf5q-r8p9-35xh"],"modified":"2026-08-12T03:51:47.490322329Z","published":"2023-09-22T16:07:02.731Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42812.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/galaxyproject/galaxy/blob/06d56c859713b74f1c2e35da1c2fcbbf0a965645/lib/galaxy/files/uris.py"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42812.json"},{"type":"ADVISORY","url":"https://github.com/galaxyproject/galaxy/security/advisories/GHSA-vf5q-r8p9-35xh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42812"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/galaxyproject/galaxy","events":[{"introduced":"0"},{"fixed":"36f049410bd12d585df9e36ecb56f0099933188b"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:galaxyproject:galaxy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"22.05"}]}}],"versions":["v22.05.1.dev0","galaxy-tool-util-20.5.0.dev2","galaxy-tool-util-20.5.0.dev1","v13.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42812.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}