PT-2024-32472 · Mender · Hosted Mender

Ole Herman S. Elgesem

·

Published

2024-11-08

·

Updated

2024-11-08

·

CVE-2024-47190

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hosted Mender versions prior to 2024.07.11
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability. This allows an attacker to forge requests from the server to other services, potentially leading to unauthorized access or data exposure. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 2024.07.11, update to a version 2024.07.11 or later to resolve the SSRF vulnerability. As a temporary workaround, consider restricting access to sensitive services and resources that could be targeted by SSRF attacks until the update is applied.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47190

Affected Products

Hosted Mender