PT-2024-25512 · Logpoint · Logpoint

Published

2024-05-07

·

Updated

2024-07-03

·

CVE-2024-33857

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Logpoint versions prior to 7.4.0
Description An issue was discovered due to a lack of input validation on URLs in threat intelligence. This allows an attacker with low-level access to the system to trigger Server Side Request Forgery.
Recommendations For versions prior to 7.4.0, update to version 7.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the threat intelligence feature to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-33857

Affected Products

Logpoint