Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-18638

Опубликовано: 11 окт. 2019
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5
CVSS3: 7.5

Описание

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.1.4-5
disco

ignored

end of life
eoan

ignored

end of life
esm-apps-legacy/xenial

released

0.9.15+debian-1ubuntu0.1~esm1
esm-apps/bionic

released

1.0.2+debian-2ubuntu0.1~esm1
esm-apps/focal

not-affected

1.1.4-5
esm-apps/jammy

not-affected

1.1.4-5
esm-apps/xenial

released

0.9.15+debian-1ubuntu0.1~esm1
esm-infra-legacy/trusty

released

0.9.12+debian-3ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 96%
0.15301
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 7 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
nvd
почти 7 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
debian
почти 7 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphi ...

CVSS3: 7.5
github
почти 7 лет назад

graphite.composer.views.send_email vulnerable to SSRF

EPSS

Процентиль: 96%
0.15301
Средний

5 Medium

CVSS2

7.5 High

CVSS3