ZeroHour

CVE-2017-14611

PoC
CVSS 3.0
9.1 critical
EPSS
2%p79
Published
()
Modified
Description

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.

Vendors
agentejo
Products
cockpit
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.