PT-2004-3373 · Myproxy · Myproxy

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2481

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: MyProxy version 6.58
Description: The issue allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions. This can be achieved by connecting to the proxy and issuing a CONNECT command.
Recommendations: For MyProxy version 6.58, consider restricting access to the proxy server to minimize the risk of exploitation. As a temporary workaround, limit the ability of remote authenticated users to issue CONNECT commands to specific hosts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2481

Affected Products

Myproxy