PT-2024-5076 · Bitdefender · Gravityzone Console
N1Nj4Sec
+1
·
Published
2024-06-06
·
Updated
2024-06-11
·
CVE-2024-4177
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
GravityZone Console versions prior to 6.38.1-2
Description:
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue is related to insufficient checking of incoming requests, which can be exploited by a remote attacker to perform an SSRF attack.
Recommendations:
For GravityZone Console versions prior to 6.38.1-2, update to version 6.38.1-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy service to minimize the risk of exploitation.
Fix
Improper Encoding or Escaping of Output
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gravityzone Console