Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Milad Fadavvi

#16949of 53,638
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2022-24469
9.8
2022-10-24
Zalando · Zalando Skipper · CVE-2022-38580
**Name of the Vulnerable Software and Affected Versions** Zalando Skipper versions prior to v0.13.237 **Description** The issue allows an attacker to exploit a vulnerable version of the proxy to access the internal metadata server or other unauthenticated URLs by adding a specific header (`X-Skipper-Proxy`) to the HTTP request. This is a case of Server-Side Request Forgery (SSRF). **Recommendations** To resolve the issue, upgrade to Zalando Skipper version v0.13.237 or later. As a temporary workaround, consider using the `dropRequestHeader("X-Skipper-Proxy")` filter to mitigate the risk of exploitation.
PT-2018-14548
6.1
2018-10-24
Wellknown · Mailcleaner · CVE-2018-18635
**Name of the Vulnerable Software and Affected Versions** MailCleaner CE versions 2018.08 through 2018.09 **Description** The issue concerns the administration login interface, where an XSS attack can be performed via the `admin/login/user/message/` PATH INFO. **Recommendations** For MailCleaner CE versions 2018.08 and 2018.09, consider restricting access to the `admin/login/user/message/` PATH INFO to minimize the risk of exploitation.