Описание
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party Advisory
- Product
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.17.1 (включая)
cpe:2.3:a:microcks:microcks:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00259
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-918
CWE-918
Связанные уязвимости
CVSS3: 9.8
github
около 2 лет назад
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
EPSS
Процентиль: 49%
0.00259
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-918
CWE-918