SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2018/Apr/15 | Exploit Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2018/Apr/15 | Exploit Mailing List Third Party Advisory |
Configurations
History
21 Nov 2024, 03:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2018/Apr/15 - Exploit, Mailing List, Third Party Advisory |
Information
Published : 2018-04-10 15:29
Updated : 2024-11-21 03:13
NVD link : CVE-2017-14611
Mitre link : CVE-2017-14611
CVE.ORG link : CVE-2017-14611
JSON object : View
Products Affected
agentejo
- cockpit
CWE
CWE-918
Server-Side Request Forgery (SSRF)