VYPR
Unrated severityNVD Advisory· Published Dec 1, 2023· Updated Aug 2, 2024

Authenticated PostHog users vulnerable to SSRF

CVE-2023-46746

Description

PostHog provides open-source product analytics, session recording, feature flagging and A/B testing that you can self-host. A server-side request forgery (SSRF), which can only be exploited by authenticated users, was found in Posthog. Posthog did not verify whether a URL was local when enabling webhooks, allowing authenticated users to forge a POST request. This vulnerability has been addressed in 22bd5942 and will be included in subsequent releases. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • PostHog/PostHogllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=1.43.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.