app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
References
Configurations
Information
Published : 2020-03-25 07:15
Updated : 2020-03-27 10:16
NVD link : CVE-2020-10791
Mitre link : CVE-2020-10791
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
it-novum
- openitcockpit