PT-2018-10685 · Searchblox · Searchblox
Ahmet Gurel
+1
·
Publicado
2018-06-05
·
Atualizado
2018-07-31
·
CVE-2018-11586
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SearchBlox version 8.6.7
Description
A XML external entity (XXE) issue in the
api/rest/status endpoint allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks by sending a crafted DTD in an XML request.Recommendations
For SearchBlox version 8.6.7, as a temporary workaround, consider disabling the
api/rest/status endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using crafted DTDs in XML requests to the affected endpoint until the issue is resolved.Exploit
Correção
XXE
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Searchblox