Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2245

Опубликовано: 04 апр. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing null-byte (%00) sequences. By crafting a request to a domain such as evil.com%00.bitdefender.com, an attacker can bypass the allowlist check, causing the proxy to forward requests to arbitrary external or internal systems.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bitdefender:gravityzone_update_server:*:*:*:*:*:*:*:*
Версия до 3.5.2.689 (исключая)

EPSS

Процентиль: 19%
0.00061
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.3
github
10 месяцев назад

A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing null-byte (%00) sequences. By crafting a request to a domain such as evil.com%00.bitdefender.com, an attacker can bypass the allowlist check, causing the proxy to forward requests to arbitrary external or internal systems.

EPSS

Процентиль: 19%
0.00061
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-918