Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-26499

Опубликовано: 15 апр. 2022
Источник: debian

Описание

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
asteriskfixed1:18.11.2~dfsg+~cs6.10.40431413-1package
asterisknot-affectedstretchpackage

Примечания

  • https://issues.asterisk.org/jira/browse/ASTERISK-29476

  • https://downloads.asterisk.org/pub/security/AST-2022-002.html

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 4 года назад

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

CVSS3: 9.1
nvd
почти 4 года назад

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

CVSS3: 9.1
github
почти 4 года назад

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.