app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
References
Configurations
History
21 Nov 2024, 04:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/it-novum/openITCOCKPIT/commit/50722befae4cfedd0103f9b0ec2a7e22530b2385 - Patch | |
References | () https://openitcockpit.io/2020/2020/03/23/openitcockpit-3-7-3-released/ - Vendor Advisory |
Information
Published : 2020-03-25 14:15
Updated : 2024-11-21 04:56
NVD link : CVE-2020-10791
Mitre link : CVE-2020-10791
CVE.ORG link : CVE-2020-10791
JSON object : View
Products Affected
it-novum
- openitcockpit
CWE
CWE-918
Server-Side Request Forgery (SSRF)