PT-2004-3373 · Myproxy · Myproxy
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-2481
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
MyProxy version 6.58
Description:
The issue allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions. This can be achieved by connecting to the proxy and issuing a CONNECT command.
Recommendations:
For MyProxy version 6.58, consider restricting access to the proxy server to minimize the risk of exploitation. As a temporary workaround, limit the ability of remote authenticated users to issue CONNECT commands to specific hosts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Myproxy