Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-528p-fqc4-66rm

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivoting requests through the server. This attack appears to be exploitable via the attacker gaining access to an administrative account, enters a URL into Upgrade Engine, and reloads the page or presses "Check Now". This vulnerability appears to have been fixed in 8.2.1.

Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivoting requests through the server. This attack appears to be exploitable via the attacker gaining access to an administrative account, enters a URL into Upgrade Engine, and reloads the page or presses "Check Now". This vulnerability appears to have been fixed in 8.2.1.

EPSS

Процентиль: 57%
0.00352
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.9
nvd
больше 7 лет назад

Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivoting requests through the server. This attack appears to be exploitable via the attacker gaining access to an administrative account, enters a URL into Upgrade Engine, and reloads the page or presses "Check Now". This vulnerability appears to have been fixed in 8.2.1.

CVSS3: 4.9
debian
больше 7 лет назад

Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery ...

EPSS

Процентиль: 57%
0.00352
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-918