PT-2022-22875 · Proxmox+1 · Proxmox Mail Gateway+2
Cursered
+1
·
Published
2022-07-08
·
Updated
2024-10-28
·
CVE-2022-35508
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) versions prior to pve-http-server 4.1-3
Description
The issue affects Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon, allowing an attacker with an unprivileged account to craft an HTTP request and achieve Server-Side Request Forgery (SSRF) and file disclosure of any files on the server. Additionally, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has been used, due to backup files having 0644 permissions and containing an authkey value.
Recommendations
For Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) versions prior to pve-http-server 4.1-3, update to pve-http-server 4.1-3 to fix the issue. As a temporary workaround, consider restricting access to the backup files and the
pve(pmg)proxy and pve(pmg)daemon components to minimize the risk of exploitation. Avoid using the backup feature until the issue is resolved.Exploit
Fix
LPE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Proxmox Mail Gateway
Proxmox Virtual Environment