SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2018/Apr/15 | Exploit Mailing List Third Party Advisory |
Configurations
Information
Published : 2018-04-10 08:29
Updated : 2022-08-18 12:44
NVD link : CVE-2017-14611
Mitre link : CVE-2017-14611
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
agentejo
- cockpit