Description
A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15743 | A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks. |
References
History
Thu, 10 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T15:00:22.287Z
Reserved: 2021-03-23T00:00:00.000Z
Link: CVE-2021-29102
Updated: 2024-08-03T22:02:50.565Z
Status : Modified
Published: 2021-07-11T02:15:07.147
Modified: 2024-11-21T06:00:43.300
Link: CVE-2021-29102
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD