PT-2020-13637 · Digdash Enterprise · Digdash

Florian Nivette

·

Published

2020-06-15

·

Updated

2020-06-24

·

CVE-2020-13650

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DigDash versions 2018R2 before p20200210 DigDash versions 2019R1 before p20200210
Description An issue was discovered in the login page, which is vulnerable to Server-Side Request Forgery (SSRF). This allows the application to be used as a proxy, and a forged request sent to an external server can disclose application credentials. For requests to internal components, the request is blind, but error messages can reveal whether the request targeted an open service.
Recommendations For DigDash versions 2018R2 before p20200210, update to a version after p20200210 to resolve the issue. For DigDash versions 2019R1 before p20200210, update to a version after p20200210 to resolve the issue. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13650

Affected Products

Digdash