PT-2022-7187 · Labstack+1 · Labstack Echo+1
Ruokeqx
·
Published
2022-09-28
·
Updated
2022-10-11
·
CVE-2022-40083
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Labstack Echo version 4.8.0
Description
The issue is related to an open redirect vulnerability via the Static Handler component, which can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF). This allows a remote attacker to perform an SSRF attack by redirecting to an untrusted site.
Recommendations
For Labstack Echo version 4.8.0, update to version 4.9.0 to resolve the issue. As a temporary workaround, consider restricting access to the Static Handler component to minimize the risk of exploitation.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Labstack Echo