Medium severity6.5NVD Advisory· Published Mar 31, 2023· Updated Jul 9, 2026
CVE-2023-27163
CVE-2023-27163
Description
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/darklynx/request-basketsGo | <= 1.2.1 | — |
Affected products
3- request-baskets/request-basketsdescription
Patches
Vulnerability mechanics
References
7- gist.github.com/b33t1e/3079c10c88cad379fb166c389ce3b7b3nvdExploitThird Party AdvisoryWEB
- notes.sjtu.edu.cn/s/MUUhEymt7nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-58g2-vgpg-335qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-27163ghsaADVISORY
- packetstormsecurity.com/files/174128/Request-Baskets-1.2.1-Server-Side-Request-Forgery.htmlnvdWEB
- packetstormsecurity.com/files/174129/Maltrail-0.53-Remote-Code-Execution.htmlnvdWEB
- request-baskets.comghsaWEB
News mentions
0No linked articles in our index yet.