• XSS.stack #1 – первый литературный журнал от юзеров форума

Web CVE-2022-41412, CVE-2022-41413

fakeid

HDD-drive
Пользователь
Регистрация
03.11.2022
Сообщения
25
Реакции
23
Гарант сделки
1
Vendor: perfSONAR
Link: https://github.com/perfsonar/
Affected Versions: v4.x <= v4.4.4
Vulnerability Type: Open Proxy Relay
Vulnerability Family: CGI Abuses
Discovered by: Ryan Moore
CVE: CVE-2022-41412
perfSONAR bundles with it a graphData.cgi script, used to graph and visualize data. There is a flaw in graphData.cgi allowing for unauthenticated users to proxy and relay HTTP/HTTPS traffic through the perfSONAR server. The vulnerability can potentially be leveraged to exfiltrate or enumerate data from internal web servers.


This vulnerability was patched in perfSONAR v4.4.5.


There is a whitelisting function that will mitigate, but is disabled by default.

https://github.com/renmizo/CVE-2022-41412
___________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________
Vendor: perfSONAR
Link: https://github.com/perfsonar/
Affected Versions: v4.x <= v4.4.5
Vulnerability Type: Partial Blind CSRF
Discovered by: Ryan Moore
CVE: CVE-2022-41413


A partial blind CSRF vulnerability exists in perfSONAR v4.x <= v4.4.5 within the /perfsonar-graphs/ test results page. Parameters and values can be injected/passed via the URL parameter, forcing the client to connect unknowingly in the background to other sites via transparent XMLHTTPRequests. This partial blind CSRF bypasses the built-in whitelisting function in perfSONAR.


This vulnerability was patched in perfSONAR v4.4.6.

 
Shodan/Fofa 2k, много ЮС
И это не RCE, а по сути http прокси. Надо крутить до RCE ...

Но важный момент:
Affected Versions: v4.x <= v4.4.4

А патч был September 20, 2022, в день релиза версии 4.4.5
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх