Description
Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.
No analysis available yet.
Remediation
Vendor Solution
Fixed in v769
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28533 | Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms. |
References
History
Thu, 03 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-10-03T13:29:38.308Z
Reserved: 2023-01-25T13:49:34.265Z
Link: CVE-2023-24515
Updated: 2024-08-02T10:56:04.284Z
Status : Modified
Published: 2023-08-22T19:16:34.480
Modified: 2024-11-21T07:48:01.870
Link: CVE-2023-24515
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD