Rewterz
Rewterz Threat Advisory – CVE-2023-42004 – IBM Security Guardium Vulnerability
November 30, 2023
Rewterz
Rewterz Threat Alert – Emerging Cyber Threat: 200 Malicious Android Apps Set Sights on Iranian Banks – Active IOCs
November 30, 2023

Rewterz Threat Advisory – CVE-2023-48711 – Node.js Google Translate Vulnerability

Severity

Low

Analysis Summary

CVE-2023-48711

Node.js Google translate api browser module is vulnerable to server-side request forgery, caused by improper input validation by the translateOptions.tld field. By sending a specially crafted request, an attacker could exploit this vulnerability to conduct SSRF attack.

Impact

  • Gain Access

Indicators Of Compromise

CVE

  • CVE-2023-48711

Affected Vendors

Node.js

Affected Products

  • Node.js Google translate api browser 4.0.0

Remediation

Upgrade to the latest version of the Google translate api browser, available from the google-translate-api-browser GIT Repository.

google-translate-api-browser GIT Repository