PT-2022-19985 · Rebuild · Rebuild

Lanfei-4

·

Published

2022-05-15

·

Updated

2022-10-29

·

CVE-2022-30049

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rebuild version 2.8.3
Description A Server-Side Request Forgery (SSRF) issue allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter. This enables attackers to access internal network details.
Recommendations For Rebuild version 2.8.3, consider restricting access to the fileurl parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the fileurl parameter in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-30049

Affected Products

Rebuild