Wekan
cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*
- <= 8.35
A server-side request forgery (SSRF) vulnerability has been identified in Wekan, an open-source kanban application built with Meteor. This vulnerability exists in versions prior to 9.32. The issue arises because webhook integration URLs are stored from user input without proper validation. These URLs are later fetched by the server, allowing an attacker to send requests to internal services or metadata endpoints. The vulnerability affects board administrators who can configure malicious webhook URLs that trigger server-side requests to private or internal resources.
Exploitation of this vulnerability allows an authenticated user with board admin privileges to access internal services, scan network resources, interact with private APIs or databases, and exfiltrate data via webhook POST payloads to internal endpoints.
Users can update to Wekan version 9.32 or later, where this vulnerability has been fixed. Instructions for downloading the latest version are available on the Wekan GitHub Releases page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.