Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-28533 Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Fixes

Solution

Fixed in v769


Workaround

No workaround given by the vendor.

History

Thu, 03 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-10-03T13:29:38.308Z

Reserved: 2023-01-25T13:49:34.265Z

Link: CVE-2023-24515

cve-icon Vulnrichment

Updated: 2024-08-02T10:56:04.284Z

cve-icon NVD

Status : Modified

Published: 2023-08-22T19:16:34.480

Modified: 2024-11-21T07:48:01.870

Link: CVE-2023-24515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.