PT-2020-12325 · Openitcockpit+1 · Openitcockpit+1
Dejan Zelic
·
Published
2020-03-25
·
Updated
2020-03-30
·
CVE-2020-10791
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
openITCOCKPIT versions prior to 3.7.3
Description
The issue allows remote authenticated users to trigger outbound TCP requests, also known as Server-Side Request Forgery (SSRF), via the Test Connection feature of the Grafana Module. This is achieved through the
GrafanaConfigurationController.php file in the app/Plugin/GrafanaModule/Controller directory.Recommendations
For versions prior to 3.7.3, update to version 3.7.3 or later to resolve the issue. As a temporary workaround, consider disabling the Test Connection feature of the Grafana Module until a patch is available. Restrict access to the
GrafanaConfigurationController.php file to minimize the risk of exploitation. Avoid using the Test Connection feature in the affected Grafana Module until the issue is resolved.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana
Openitcockpit