Описание
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.0 (исключая)
Одно из
cpe:2.3:a:vembu:bdr_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:vembu:offsite_dr:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:vembu:offsite_dr:4.2.0.1:*:*:*:*:*:*:*
EPSS
Процентиль: 46%
0.00234
Низкий
8.6 High
CVSS3
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Vembu BDR Suite before 4.2.0 allows Unauthenticated SSRF via a GET request that specifies a hostname and port number.
EPSS
Процентиль: 46%
0.00234
Низкий
8.6 High
CVSS3
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352