PT-2023-31052 · Unknown · Symbolicator

Oioki

·

Publicado

2023-11-30

·

Atualizado

2023-12-12

·

CVE-2023-49094

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Symbolicator versions prior to 23.11.2
Description The issue allows an attacker to make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on a Sentry instance.
Recommendations For versions prior to 23.11.2, update to version 23.11.2 to resolve the issue. As a temporary workaround, consider restricting access to the Symbolicator service to minimize the risk of exploitation. Avoid using specially crafted HTTP endpoints in the affected Symbolicator instance until the issue is resolved.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49094
GHSA-6576-PR6J-H9C6

Produtos afetados

Symbolicator