PT-2022-7187 · Labstack+1 · Labstack Echo+1

Ruokeqx

·

Published

2022-09-28

·

Updated

2022-10-11

·

CVE-2022-40083

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Labstack Echo version 4.8.0
Description The issue is related to an open redirect vulnerability via the Static Handler component, which can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF). This allows a remote attacker to perform an SSRF attack by redirecting to an untrusted site.
Recommendations For Labstack Echo version 4.8.0, update to version 4.9.0 to resolve the issue. As a temporary workaround, consider restricting access to the Static Handler component to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2023-08980
CVE-2022-40083
GHSA-CRXJ-HRMP-4RWF
GO-2022-1031

Affected Products

Debian
Labstack Echo