PT-2021-18207 · Sydent · Sydent
Richvdh
·
Published
2021-04-15
·
Updated
2021-04-22
·
CVE-2021-29431
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Sydent versions prior to the versions including fixes 9e57334, 8936925, 3d531ed, 0f00412
Description:
The issue allows Sydent to be induced to send HTTP GET requests to internal systems due to a lack of parameter validation or IP address blacklisting. Although it is not possible to exfiltrate data or control request headers, the attack might be used to perform an internal port enumeration.
Recommendations:
For versions prior to the fixed versions, update to a version that includes the fixes 9e57334, 8936925, 3d531ed, 0f00412 to resolve the issue.
As a temporary workaround, consider configuring a firewall to prevent Sydent from reaching internal HTTP resources.
Fix
SSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sydent