CVE-2021-29357

The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:outsystems:lifetime_management_console:*:*:*:*:*:*:*:*
cpe:2.3:a:outsystems:outsystems:*:*:*:*:*:*:*:*
cpe:2.3:a:outsystems:platform_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-04-12 19:15

Updated : 2024-02-28 18:28


NVD link : CVE-2021-29357

Mitre link : CVE-2021-29357

CVE.ORG link : CVE-2021-29357


JSON object : View

Products Affected

outsystems

  • lifetime_management_console
  • outsystems
  • platform_server
CWE
CWE-918

Server-Side Request Forgery (SSRF)