An authenticated Server-Side Request Forgery (SSRF) vulnerability existed in the upload functionality.
Authenticated users with create or update access to an upload-enabled collection could cause the server to make outbound HTTP requests to arbitrary URLs.
Consumers are affected if ALL of these are true:
upload enabledcreate or update access to that collectionThis vulnerability has been patched in v3.79.1. Users should upgrade to v3.79.1 or later.
Until consumers can upgrade:
create and update access to upload-enabled collections to trusted roles only.3.79.1Exploitability
AV:NAC:LPR:LUI:NScope
S:CImpact
C:HI:NA:N7.7/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N