PT-2023-29919 · Apache · Apache

0X41C

·

Publicado

2023-10-31

·

Atualizado

2023-11-08

·

CVE-2023-46236

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FOG versions prior to 1.5.10
Description A server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme. This also allows remote access to files visible to the Apache user group. Other impacts vary based on server configuration.
Recommendations For versions prior to 1.5.10, update to version 1.5.10 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and configuring the server to minimize the risk of exploitation.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46236
GHSA-8QG4-9363-873H

Produtos afetados

Apache