RULE(RULE ID:338232)

Rule General Information
Release Date: 2024-07-09
Rule Name: Apache ServiceComb Service-Center SSRF Vulnerability (CVE-2023-44313)
Severity:
CVE ID:
Rule Protection Details
Description: Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include).Users are recommended to upgrade to version 2.2.0, which fixes the issue.
Impact: SSRF is a security vulnerability constructed by an attacker to form a request initiated by a server. By exploiting this vulnerability, an attacker can bypass access restrictions such as firewalls, thereby using an infected or vulnerable server as a proxy for port scanning and even accessing internal system data.
Affected OS: Windows, Linux, Others
Reference: http://www.openwall.com/lists/oss-security/2024/01/31/4
https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5r
Solutions
Refer to the announcement or patch by the vendor: https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5r