A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.
History

Thu, 31 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Eladmin
Eladmin eladmin
Weaknesses CWE-918
CPEs cpe:2.3:a:eladmin:eladmin:2.7:*:*:*:*:*:*:*
Vendors & Products Eladmin
Eladmin eladmin
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-30T00:00:00

Updated: 2024-10-31T15:21:43.482Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-51242

cve-icon Vulnrichment

Updated: 2024-10-31T15:20:28.259Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-30T21:15:14.793

Modified: 2024-11-01T12:57:03.417

Link: CVE-2024-51242

cve-icon Redhat

No data.