Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-0889

Опубликовано: 21 апр. 2017
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.

Отчет

Red Hat CloudForms 4shipped the vulnerable paperclip ruby gem, however this ruby gem was removed in CloudForms 5.8. As this issue has been addressed in CloudForms 5.8, and the issue is only rated moderate Red Hat Security will not be fixing this issue in CloudForms 5.7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5paperclipWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=1513542paperclip: SSRF vulnerability in the Paperclip::UriAdapter class

EPSS

Процентиль: 57%
0.00344
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.

CVSS3: 9.8
github
около 8 лет назад

paperclip Server-Side Request Forgery vulnerability

EPSS

Процентиль: 57%
0.00344
Низкий

4.3 Medium

CVSS3