PT-2022-11274 · Unknown · Ips Community Suite

Mikhail Klyuchnikov

·

Published

2022-06-13

·

Updated

2022-06-27

·

CVE-2021-40604

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IPS Community Suite versions prior to 4.6.2
Description A Server-Side Request Forgery (SSRF) issue allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases, exploitation is possible by an unauthenticated user. The gkey parameter is an unfollow token and is involved in the vulnerability.
Recommendations For IPS Community Suite versions prior to 4.6.2, update to version 4.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the phar protocol and dynamically generated class names to minimize the risk of exploitation. Avoid using the gkey parameter in sensitive operations until the issue is resolved.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40604

Affected Products

Ips Community Suite