PT-2021-18207 · Sydent · Sydent

Richvdh

·

Published

2021-04-15

·

Updated

2021-04-22

·

CVE-2021-29431

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Sydent versions prior to the versions including fixes 9e57334, 8936925, 3d531ed, 0f00412
Description: The issue allows Sydent to be induced to send HTTP GET requests to internal systems due to a lack of parameter validation or IP address blacklisting. Although it is not possible to exfiltrate data or control request headers, the attack might be used to perform an internal port enumeration.
Recommendations: For versions prior to the fixed versions, update to a version that includes the fixes 9e57334, 8936925, 3d531ed, 0f00412 to resolve the issue. As a temporary workaround, consider configuring a firewall to prevent Sydent from reaching internal HTTP resources.

Fix

SSRF

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29431
GHSA-9JHM-8M8C-C3F4
PYSEC-2021-22

Affected Products

Sydent