PT-2024-22164 · Akana · Akana Community Manager Developer Portal+1

Published

2024-04-18

·

Updated

2024-08-02

·

CVE-2024-2796

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Akana API Platform versions prior to and including 2022.1.3 Akana Community Manager Developer Portal versions prior to and including 2022.1.3
Description A server-side request forgery (SSRF) issue was discovered. This issue allows an attacker to forge requests from the server, potentially leading to unauthorized access to internal resources.
Recommendations For Akana API Platform versions prior to and including 2022.1.3, update to a version later than 2022.1.3 to resolve the issue. For Akana Community Manager Developer Portal versions prior to and including 2022.1.3, update to a version later than 2022.1.3 to resolve the issue.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-2796

Affected Products

Akana Api Platform
Akana Community Manager Developer Portal