|
|||
Rule General Information |
---|
Release Date: | 2024-07-09 | |
Rule Name: | Apache ServiceComb Service-Center SSRF Vulnerability (CVE-2023-44313) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include).Users are recommended to upgrade to version 2.2.0, which fixes the issue. | |
Impact: | SSRF is a security vulnerability constructed by an attacker to form a request initiated by a server. By exploiting this vulnerability, an attacker can bypass access restrictions such as firewalls, thereby using an infected or vulnerable server as a proxy for port scanning and even accessing internal system data. | |
Affected OS: | Windows, Linux, Others | |
Reference: | http://www.openwall.com/lists/oss-security/2024/01/31/4 https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5r |
|
Solutions |
---|
Refer to the announcement or patch by the vendor: https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5r |