Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alexandre Basquin

#34050de 53,630
7.7CVSS total
Vulnerabilidades · 1
PT-2019-18683
7.7
2019-05-09
Thehive · Cortex-Analyzers · CVE-2019-7652
**Name of the Vulnerable Software and Affected Versions** TheHive Project UnshortenLink analyzer versions prior to 1.1 Cortex-Analyzers versions prior to 1.15.2 **Description** The issue allows for Server-Side Request Forgery (SSRF) attacks. An attacker can exploit this by creating a new analysis, selecting URL for Data Type, and providing an SSRF payload in the `Data` parameter, such as "http://127.0.0.1:22". The result of the attack can be seen in the main dashboard, enabling potential port scans on localhost and intranet hosts. **Recommendations** For TheHive Project UnshortenLink analyzer versions prior to 1.1, update to version 1.1 or later. For Cortex-Analyzers versions prior to 1.15.2, update to version 1.15.2 or later.