Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89fc-cvxq-q6pv

Опубликовано: 08 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.

EPSS

Процентиль: 41%
0.0019
Низкий

8.8 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.4
nvd
почти 4 года назад

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.

EPSS

Процентиль: 41%
0.0019
Низкий

8.8 High

CVSS3

Дефекты

CWE-918