Description
This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
Published: 2024-03-14
Score: 6.5 Medium
EPSS: 9.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jan 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Papercut
Papercut papercut Mf
Papercut papercut Ng
CPEs cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Papercut
Papercut papercut Mf
Papercut papercut Ng

Subscriptions

Apple Macos
Linux Linux Kernel
Microsoft Windows
Papercut Papercut Mf Papercut Ng
cve-icon MITRE

Status: PUBLISHED

Assigner: PaperCut

Published:

Updated: 2024-08-28T15:12:02.085Z

Reserved: 2024-02-26T05:36:24.198Z

Link: CVE-2024-1884

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.318Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-14T04:15:08.697

Modified: 2025-01-23T21:06:27.910

Link: CVE-2024-1884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses