Описание
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
A flaw was found in the console component. An authenticated user can exploit a Server-Side Request Forgery (SSRF) vulnerability by manipulating the towerHost parameter when accessing the /ansibletower handler. This allows the user to bypass pathname validation and access arbitrary internal or external hosts. The primary consequence is the exfiltration of full HTTP responses, leading to information disclosure from the affected system.
Отчет
This Important vulnerability in the console component allows an authenticated Red Hat Advanced Cluster Management (ACM) console user to perform Server-Side Request Forgery (SSRF). This enables the attacker to access arbitrary internal or external hosts from the hub's network position and exfiltrate full HTTP responses, bypassing existing pathname restrictions due to control over the hostname.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
EPSS
7.7 High
CVSS3