Description
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24415 | An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible. |
References
History
No history.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2024-08-04T01:30:08.972Z
Reserved: 2021-08-03T00:00:00.000Z
Link: CVE-2021-37940
No data.
Status : Modified
Published: 2021-12-07T19:15:07.493
Modified: 2024-11-21T06:16:06.910
Link: CVE-2021-37940
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD