Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qx3-xhmf-4jcc

Опубликовано: 29 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

EPSS

Процентиль: 29%
0.00103
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

EPSS

Процентиль: 29%
0.00103
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918