Описание
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00704
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918
Связанные уязвимости
EPSS
Процентиль: 72%
0.00704
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918