Количество 2
Количество 2
CVE-2022-23206
около 4 лет назад
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.
CVSS3: 7.5
EPSS: Низкий
GHSA-wp47-9r3h-xfgq
около 4 лет назад
Server-Side Request Forgery in Apache Traffic Control
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-23206 In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-wp47-9r3h-xfgq Server-Side Request Forgery in Apache Traffic Control | CVSS3: 7.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу
20