Описание
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.
Ссылки
- Patch
- ExploitThird Party Advisory
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2023-09-18 (исключая)
cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.00021
Низкий
2 Low
CVSS3
2.3 Low
CVSS3
Дефекты
CWE-918
CWE-918
EPSS
Процентиль: 5%
0.00021
Низкий
2 Low
CVSS3
2.3 Low
CVSS3
Дефекты
CWE-918
CWE-918