Логотип exploitDog
bind:CVE-2017-18638
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-18638

Количество 5

Количество 5

ubuntu логотип

CVE-2017-18638

больше 6 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2017-18638

больше 6 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2017-18638

больше 6 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2017-18638

больше 6 лет назад

send_email in graphite-web/webapp/graphite/composer/views.py in Graphi ...

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-vfj6-275q-4pvm

больше 6 лет назад

graphite.composer.views.send_email vulnerable to SSRF

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-18638

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
91%
Критический
больше 6 лет назад
redhat логотип
CVE-2017-18638

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
91%
Критический
больше 6 лет назад
nvd логотип
CVE-2017-18638

send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.

CVSS3: 7.5
91%
Критический
больше 6 лет назад
debian логотип
CVE-2017-18638

send_email in graphite-web/webapp/graphite/composer/views.py in Graphi ...

CVSS3: 7.5
91%
Критический
больше 6 лет назад
github логотип
GHSA-vfj6-275q-4pvm

graphite.composer.views.send_email vulnerable to SSRF

CVSS3: 7.5
91%
Критический
больше 6 лет назад

Уязвимостей на страницу