mitmproxy
cpe:2.3:a:mitmproxy:mitmproxy:*:*:*:*:*:*:*
- <= 11.1.1
A vulnerability in mitmweb versions through 11.1.1 allows a malicious client to use the proxy server to access mitmweb's internal API, which is normally restricted to localhost. This access could potentially be exploited to execute remote code. The issue does not affect the mitmproxy or mitmdump tools. The vulnerability arises because the proxy server, bound to all interfaces by default, can be used to reach the internal API, creating a server-side request forgery (SSRF) scenario. An attacker would need to be on the same local network, as connections from publicly-routable IP addresses are blocked by default.
Exploitation of this vulnerability could lead to unauthorized access to mitmweb's internal API and potentially allow for remote code execution on the server.
Users are advised to upgrade to mitmproxy version 11.1.2 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.