PT-2023-29919 · Apache · Apache
0X41C
·
Published
2023-10-31
·
Updated
2023-11-08
·
CVE-2023-46236
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FOG versions prior to 1.5.10
Description
A server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme. This also allows remote access to files visible to the Apache user group. Other impacts vary based on server configuration.
Recommendations
For versions prior to 1.5.10, update to version 1.5.10 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and configuring the server to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache