High severity8.1OSV Advisory· Published Feb 6, 2018· Updated Jun 17, 2026
CVE-2017-6201
CVE-2017-6201
Description
A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the attackers from accessing the URLs directly.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2v0.101, v0.102, v0.103, …+ 1 more
- (no CPE)range: v0.101, v0.102, v0.103, …
- (no CPE)range: <0.203
Patches
Vulnerability mechanics
References
3- github.com/sandstorm-io/sandstorm/commit/164997fb958effbc90c5328c166706280a84aaa1nvdPatchThird Party Advisory
- devco.re/blog/2018/01/26/Sandstorm-Security-Review-CVE-2017-6200-en/nvdExploitThird Party Advisory
- sandstorm.io/news/2017-03-02-security-reviewnvdVendor Advisory
News mentions
0No linked articles in our index yet.