Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q445-cmjc-pjfp

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.

EPSS

Процентиль: 62%
0.00428
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.

EPSS

Процентиль: 62%
0.00428
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918