Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-35508

Опубликовано: 04 дек. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:proxmox:proxmox_mail_gateway:-:*:*:*:*:*:*:*
cpe:2.3:a:proxmox:pve_http_server:*:*:*:*:*:*:*:*
Версия до 4.1-3 (исключая)
cpe:2.3:a:proxmox:virtual_environment:-:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00123
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918
CWE-918

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.

EPSS

Процентиль: 32%
0.00123
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918
CWE-918