PT-2019-5495 · Joey Hess · Ikiwiki

Publicado

2019-02-10

·

Atualizado

2024-06-15

·

CVE-2019-9187

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ikiwiki versions prior to 3.20170111.1 ikiwiki versions 3.2018x ikiwiki versions 3.2019x prior to 3.20190228
Description The issue allows for Server-Side Request Forgery (SSRF) via the aggregate plugin, which can also be used to read local files through file: URIs. This can enable a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 3.20170111.1, update to version 3.20170111.1 or later. For versions 3.2018x, consider disabling the aggregate plugin until a patch is available. For versions 3.2019x prior to 3.20190228, update to version 3.20190228 or later. As a temporary workaround, consider restricting access to the aggregate plugin to minimize the risk of exploitation.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-03290
CVE-2019-9187
DLA-1716-1
DSA-4399-1
MGASA-2019-0113
OPENSUSE-SU-2024:10860-1

Produtos afetados

Ikiwiki