Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43f8-p5w3-5m25

Опубликовано: 11 фев. 2021
Источник: github
Github: Прошло ревью

Описание

vrana/adminer vulnerable to SSRF by connecting to privileged ports

Impact

All users are affected.

Patches

  • Unsuccessfully patched by 0fae40fb, included in version 4.4.0.
  • Patched by 35bfaa75, included in version 4.7.8.

Workarounds

Protect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin.

References

For more information

If you have any questions or comments about this advisory:

  • Comment at 35bfaa75.

Пакеты

Наименование

vrana/adminer

composer
Затронутые версииВерсия исправления

< 4.7.8

4.7.8

EPSS

Процентиль: 92%
0.0773
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

Adminer through 4.3.1 has SSRF via the server parameter.

CVSS3: 9.8
nvd
почти 8 лет назад

Adminer through 4.3.1 has SSRF via the server parameter.

CVSS3: 9.8
debian
почти 8 лет назад

Adminer through 4.3.1 has SSRF via the server parameter.

suse-cvrf
почти 8 лет назад

Security update for adminer

EPSS

Процентиль: 92%
0.0773
Низкий

Дефекты

CWE-918