Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000139

Опубликовано: 03 нояб. 2017
Источник: debian
EPSS Низкий

Описание

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mahararemovedpackage

EPSS

Процентиль: 43%
0.00206
Низкий

Связанные уязвимости

CVSS3: 8
nvd
больше 8 лет назад

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

CVSS3: 8
github
больше 3 лет назад

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

EPSS

Процентиль: 43%
0.00206
Низкий