PT-2024-19593 · Tencent · Tencent Blueking Cmdb
Exp1Orer
·
Published
2024-02-26
·
Updated
2025-06-09
·
CVE-2024-22873
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Tencent Blueking CMDB versions 3.2.x through 3.9.x
Description
The issue is related to a Server-Side Request Forgery (SSRF) that affects the event subscription function. This allows attackers to access internal requests via a crafted POST request to the "/service/subscription.go" endpoint. The
event subscription function is the vulnerable component, and the exploitation involves sending a crafted POST request.Recommendations
For versions 3.2.x through 3.9.x, consider disabling the event subscription function until a patch is available. Restrict access to the "/service/subscription.go" endpoint to minimize the risk of exploitation. Avoid using the event subscription function in the affected API endpoint until the issue is resolved.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tencent Blueking Cmdb