PT-2021-7404 · Unknown · Hubs Cloud Reticulum
Torsten Trumm
·
Published
2021-05-06
·
Updated
2021-06-30
·
CVE-2021-29954
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hubs Cloud Reticulum versions prior to 1.0.1/20210428201255
Description
The issue is related to an insecure configuration of the proxy server in the Hubs Cloud Reticulum software. This allows a remote attacker to exploit the vulnerability and potentially disclose protected information. The proxy functionality in the software permits access to internal URLs, including the metadata service.
Recommendations
For versions prior to 1.0.1/20210428201255, consider disabling the proxy functionality as a temporary workaround until a patch is available. Restrict access to internal URLs, including the metadata service, to minimize the risk of exploitation.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hubs Cloud Reticulum