Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgcg-p3v2-9h4p

Опубликовано: 30 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Externally Controlled Reference to a Resource in Another Sphere and Confused Deputy in Spring Cloud Netflix

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

Пакеты

Наименование

org.springframework.cloud:spring-cloud-netflix

maven
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.4

2.2.4

Наименование

org.springframework.cloud:spring-cloud-netflix

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.6

2.1.6

EPSS

Процентиль: 100%
0.92376
Критический

6.5 Medium

CVSS3

Дефекты

CWE-441
CWE-610

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

EPSS

Процентиль: 100%
0.92376
Критический

6.5 Medium

CVSS3

Дефекты

CWE-441
CWE-610