Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgh2-q3fc-jjmr

Опубликовано: 12 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.

EPSS

Процентиль: 54%
0.00316
Низкий

7.7 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.7
nvd
около 1 года назад

Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.

CVSS3: 7.7
fstec
около 1 года назад

Уязвимость программных платформ для разработки и управления онлайн магазинами Adobe Commerce и Magento Open Source, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 54%
0.00316
Низкий

7.7 High

CVSS3

Дефекты

CWE-918