The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1478792 | Issue Tracking Third Party Advisory |
https://access.redhat.com/errata/RHSA-2017:2675 | |
https://access.redhat.com/errata/RHSA-2017:2674 |
Configurations
Information
Published : 2017-09-28 18:34
Updated : 2023-02-12 15:31
NVD link : CVE-2017-7553
Mitre link : CVE-2017-7553
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
redhat
- mobile_application_platform