Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fw4p-qcqm-jgpq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

EPSS

Процентиль: 86%
0.02902
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 10 лет назад

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

fstec
около 10 лет назад

Уязвимость интерпретатора ColdFusion, позволяющая нарушителю перенаправить HTTP-трафик на внутренние серверы

EPSS

Процентиль: 86%
0.02902
Низкий

Дефекты

CWE-20