PT-2021-14243 · Unknown · Groupsession Zion+2
Ryo Sato
·
Published
2021-07-28
·
Updated
2021-08-06
·
CVE-2021-20788
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GroupSession Free edition versions 2.2.0 through 5.1.0
GroupSession byCloud versions 3.0.3 through 5.1.0
GroupSession ZION versions 3.0.3 through 5.1.0
Description:
A server-side request forgery (SSRF) issue allows a remote authenticated attacker to conduct a port scan from the product and/or obtain information from the internal Web server.
Recommendations:
For GroupSession Free edition versions 2.2.0 through 5.1.0, update to version 5.1.0 or later.
For GroupSession byCloud versions 3.0.3 through 5.1.0, update to version 5.1.0 or later.
For GroupSession ZION versions 3.0.3 through 5.1.0, update to version 5.1.0 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Groupsession Free Edition
Groupsession Zion
Groupsession Bycloud