PT-2021-7404 · Unknown · Hubs Cloud Reticulum

Torsten Trumm

·

Published

2021-05-06

·

Updated

2021-06-30

·

CVE-2021-29954

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hubs Cloud Reticulum versions prior to 1.0.1/20210428201255
Description The issue is related to an insecure configuration of the proxy server in the Hubs Cloud Reticulum software. This allows a remote attacker to exploit the vulnerability and potentially disclose protected information. The proxy functionality in the software permits access to internal URLs, including the metadata service.
Recommendations For versions prior to 1.0.1/20210428201255, consider disabling the proxy functionality as a temporary workaround until a patch is available. Restrict access to internal URLs, including the metadata service, to minimize the risk of exploitation.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06010
CVE-2021-29954

Affected Products

Hubs Cloud Reticulum