Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jay Wu

Researcher fromAcer Cyber Security Inc., ACSI
#48155of 53,632
5.3Total CVSS
Vulnerabilities · 1
PT-2022-24700
5.3
2022-10-18
Unknown · Rava Certificate Validation System · CVE-2022-39055
**Name of the Vulnerable Software and Affected Versions** RAVA certificate validation system (affected versions not specified) **Description** The RAVA certificate validation system has inadequate filtering for the `URL parameter`, allowing an unauthenticated remote attacker to perform a Server-Side Request Forgery (SSRF) attack. This can enable the attacker to discover the internal network topology based on the query response. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.