A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.

We have already fixed the vulnerability in the following versions:
QuLog Center 1.7.0.829 ( 2024/10/01 ) and later
QuLog Center 1.8.0.888 ( 2024/10/15 ) and later
QTS 4.5.4.2957 build 20241119 and later
QuTS hero h4.5.4.2956 build 20241119 and later
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54244 A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later
Fixes

Solution

We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later


Workaround

No workaround given by the vendor.

History

Sat, 06 Dec 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Qnap
Qnap qts
Qnap qulog Center
Qnap quts Hero
CPEs cpe:2.3:a:qnap:qulog_center:*:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:*:-:*:*:*:*:*:*
cpe:2.3:o:qnap:quts_hero:*:-:*:*:*:*:*:*
Vendors & Products Qnap
Qnap qts
Qnap qulog Center
Qnap quts Hero
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Fri, 07 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later
Title QuLog Center
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2025-03-07T17:54:11.651Z

Reserved: 2024-11-22T06:21:49.206Z

Link: CVE-2024-53696

cve-icon Vulnrichment

Updated: 2025-03-07T17:54:07.692Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-07T17:15:20.390

Modified: 2025-12-06T00:34:08.557

Link: CVE-2024-53696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses