PostHog
cpe:2.3:a:posthog:posthog:*:*:*:*:*:*:*
A server-side request forgery (SSRF) vulnerability has been identified in PostHog, specifically within the 'database_schema' method. This vulnerability arises from inadequate validation of URIs before accessing resources, enabling authenticated remote attackers to disclose sensitive information in the context of the service account.
Exploitation of this vulnerability could lead to unauthorized information disclosure from the PostHog database.
PostHog has released a patch for this vulnerability. Users should update to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.