PT-2021-15298 · Concrete5 · Concrete5

Pabl00Nicarres

·

Published

2021-10-07

·

Updated

2021-11-01

·

CVE-2021-22958

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions concrete5 versions prior to 8.5.5
Description A Server-Side Request Forgery issue was found that allows a decimal notation encoded IP address to bypass localhost limitations, enabling interaction with local services. The impact varies depending on the services exposed.
Recommendations For versions prior to 8.5.5, update to version 8.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to local services to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22958
GHSA-284F-F2HW-J2GX

Affected Products

Concrete5