PT-2023-31052 · Unknown · Symbolicator
Oioki
·
Publicado
2023-11-30
·
Atualizado
2023-12-12
·
CVE-2023-49094
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Symbolicator versions prior to 23.11.2
Description
The issue allows an attacker to make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on a Sentry instance.
Recommendations
For versions prior to 23.11.2, update to version 23.11.2 to resolve the issue. As a temporary workaround, consider restricting access to the Symbolicator service to minimize the risk of exploitation. Avoid using specially crafted HTTP endpoints in the affected Symbolicator instance until the issue is resolved.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Symbolicator