A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.
Existe una vulnerabilidad CWE-918: Server-Side Request Forgery (SSRF) que podría provocar la ejecución de código remoto no autenticado cuando se accede al servidor a través de la red con conocimiento de URL ocultas y manipulación del encabezado de solicitud del host.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Attack Requirements | PRESENT |
| Privileges Required | NONE |
| User Interaction | NONE |
| Vulnerability Confidentiality | LOW |
| Vulnerability Integrity | LOW |
| Vulnerability Availability | NONE |
| Subsequent Confidentiality | LOW |
| Subsequent Integrity | NONE |
| Subsequent Availability | NONE |
Source: [email protected]
Type: Secondary
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-918
|