CVE-2020-23079: Halo

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.

Affected products

  • Halo Halo: up to and including 1.3.2

Published 2021-07-12. Last modified 2026-06-17.