Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f274-c23v-hx4j

Опубликовано: 30 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

EPSS

Процентиль: 1%
0.00105
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.4
redhat
2 месяца назад

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

CVSS3: 4.4
nvd
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

CVSS3: 4.4
debian
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in ...

EPSS

Процентиль: 1%
0.00105
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-918