PT-2021-15304 · Unknown · Concrete Cms
Adrian Tiron
+1
·
Published
2021-11-19
·
Updated
2021-11-23
·
CVE-2021-22969
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions below 8.5.7
Concrete CMS version 9.0.0 is not affected as it includes the fix.
Description
The issue concerns a SSRF mitigation bypass using a DNS Rebind attack, allowing an attacker to fetch cloud IAAS IAM keys. To address this, Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading, rather than relying on DNS. A mitigation for this issue is to ensure IMDS configurations follow a cloud provider's best practices.
Recommendations
For Concrete CMS versions below 8.5.7, update to version 8.5.7 or later to fix the issue.
For users who cannot update immediately, consider implementing the mitigation by ensuring IMDS configurations are according to a cloud provider's best practices.
As a temporary workaround, consider restricting downloads from the local network and specifying validated IPs when downloading to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms