PT-2024-19593 · Tencent · Tencent Blueking Cmdb

Exp1Orer

·

Published

2024-02-26

·

Updated

2025-06-09

·

CVE-2024-22873

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tencent Blueking CMDB versions 3.2.x through 3.9.x
Description The issue is related to a Server-Side Request Forgery (SSRF) that affects the event subscription function. This allows attackers to access internal requests via a crafted POST request to the "/service/subscription.go" endpoint. The event subscription function is the vulnerable component, and the exploitation involves sending a crafted POST request.
Recommendations For versions 3.2.x through 3.9.x, consider disabling the event subscription function until a patch is available. Restrict access to the "/service/subscription.go" endpoint to minimize the risk of exploitation. Avoid using the event subscription function in the affected API endpoint until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-22873

Affected Products

Tencent Blueking Cmdb