Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45152

Опубликовано: 17 окт. 2023
Источник: nvd
CVSS3: 2
CVSS3: 2.3
EPSS Низкий

Описание

Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:*
Версия до 2023-09-18 (исключая)

EPSS

Процентиль: 5%
0.00021
Низкий

2 Low

CVSS3

2.3 Low

CVSS3

Дефекты

CWE-918
CWE-918

EPSS

Процентиль: 5%
0.00021
Низкий

2 Low

CVSS3

2.3 Low

CVSS3

Дефекты

CWE-918
CWE-918