Описание
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
Ссылки
- PatchVendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:webwasher:webwasher_classic:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:webwasher:webwasher_classic:3.3:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.13907
Средний
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
EPSS
Процентиль: 94%
0.13907
Средний
7.5 High
CVSS2
Дефекты
NVD-CWE-Other