send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-10-11T22:01:28

Updated: 2024-08-05T21:28:55.975Z

Reserved: 2019-10-11T00:00:00

Link: CVE-2017-18638

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-11T23:15:10.447

Modified: 2019-10-21T16:15:13.477

Link: CVE-2017-18638

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-10-12T00:00:00Z

Links: CVE-2017-18638 - Bugzilla