PT-2018-15196 · Pydio · Pydio

Mike Gualtieri

·

Published

2018-07-23

·

Updated

2018-09-20

·

CVE-2018-1999017

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pydio versions 8.2.0 and earlier
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability in the getUpgradePath($url) function, located in plugins/action.updater/UpgradeManager.php. This vulnerability can be exploited by an authenticated admin user who enters a URL into the Upgrade Engine and then reloads the page or presses "Check Now", allowing the attacker to request arbitrary URLs and pivot requests through the server.
Recommendations For Pydio versions 8.2.0 and earlier, update to version 8.2.1 to resolve the issue.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1999017

Affected Products

Pydio