CVE-2021-29357

The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:outsystems:lifetime_management_console:*:*:*:*:*:*:*:*
cpe:2.3:a:outsystems:outsystems:*:*:*:*:*:*:*:*
cpe:2.3:a:outsystems:platform_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:00

Type Values Removed Values Added
References () https://labs.integrity.pt/advisories/cve-2021-29357/ - Third Party Advisory () https://labs.integrity.pt/advisories/cve-2021-29357/ - Third Party Advisory
References () https://success.outsystems.com/Support/Security/Vulnerabilities/Vulnerability_RTAF-2226 - Vendor Advisory () https://success.outsystems.com/Support/Security/Vulnerabilities/Vulnerability_RTAF-2226 - Vendor Advisory

Information

Published : 2021-04-12 19:15

Updated : 2024-11-21 06:00


NVD link : CVE-2021-29357

Mitre link : CVE-2021-29357

CVE.ORG link : CVE-2021-29357


JSON object : View

Products Affected

outsystems

  • platform_server
  • outsystems
  • lifetime_management_console
CWE
CWE-918

Server-Side Request Forgery (SSRF)