CVE-2022-39055

RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:changingtec:rava_certificate_validation_system:3:*:*:*:*:*:*:*

Information

Published : 2022-10-17 23:15

Updated : 2022-10-20 08:07


NVD link : CVE-2022-39055

Mitre link : CVE-2022-39055


JSON object : View

CWE
CWE-918

Server-Side Request Forgery (SSRF)

Advertisement

dedicated server usa

Products Affected

changingtec

  • rava_certificate_validation_system