Known Vulnerabilities
CVE-2024-4399
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
CRITICAL
CVSS 9.1
Published May 23, 2024
CVE-2024-4388
This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server
HIGH
CVSS 7.5
Published May 23, 2024