PT-2022-11274 · Unknown · Ips Community Suite
Mikhail Klyuchnikov
·
Published
2022-06-13
·
Updated
2022-06-27
·
CVE-2021-40604
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IPS Community Suite versions prior to 4.6.2
Description
A Server-Side Request Forgery (SSRF) issue allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases, exploitation is possible by an unauthenticated user. The
gkey parameter is an unfollow token and is involved in the vulnerability.Recommendations
For IPS Community Suite versions prior to 4.6.2, update to version 4.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the phar protocol and dynamically generated class names to minimize the risk of exploitation. Avoid using the
gkey parameter in sensitive operations until the issue is resolved.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ips Community Suite