Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6201

Опубликовано: 06 фев. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the attackers from accessing the URLs directly.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sandstorm:sandstorm:*:*:*:*:*:*:*:*
Версия до 0.203 (исключая)

EPSS

Процентиль: 26%
0.00091
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the attackers from accessing the URLs directly.

EPSS

Процентиль: 26%
0.00091
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-918