Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m9g-hh42-2p58

Опубликовано: 26 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.

EPSS

Процентиль: 41%
0.00189
Низкий

8.1 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.1
nvd
почти 2 года назад

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.

EPSS

Процентиль: 41%
0.00189
Низкий

8.1 High

CVSS3

Дефекты

CWE-918