CVE-2023-32750: Pydio Cells
Medium severity, CVSS 6.5. EPSS: 3.8% chance of exploitation in the next 30 days.
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.
Affected products
- Pydio Cells: before 3.0.12 (fixed in 3.0.12); from 4.1.0, before 4.1.3 (fixed in 4.1.3)
Published 2023-06-08. Last modified 2026-06-17.