Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8f9-449c-rf6m

Опубликовано: 06 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.

EPSS

Процентиль: 32%
0.00121
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость прокси-сервера операционной системы Ruijie Reyee OS, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 32%
0.00121
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-918