CVE-2022-39055

RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html Third Party Advisory VDB Entry
https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:changingtec:rava_certificate_validation_system:3:*:*:*:*:*:*:*

History

21 Nov 2024, 07:17

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html - Third Party Advisory, VDB Entry () https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html - Third Party Advisory, VDB Entry

Information

Published : 2022-10-18 06:15

Updated : 2024-11-21 07:17


NVD link : CVE-2022-39055

Mitre link : CVE-2022-39055

CVE.ORG link : CVE-2022-39055


JSON object : View

Products Affected

changingtec

  • rava_certificate_validation_system
CWE
CWE-918

Server-Side Request Forgery (SSRF)