CVE-2019-7652
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main dashboard. Thus, it is possible to do port scans on localhost and intranet hosts.
El analizador UnshortenLink Project UnshortenLink, versiones anteriores a 1.1, incluido en Cortex-Analyzers con versiones anteriores a 1.15.2, es vulnerable a un ataque SSRF. Para explotar la vulnerabilidad, un atacante debe crear un nuevo análisis, seleccionar URL para Data Type y proporcionar un payload SSRF como "http://127.0.0.1:22" en el parámetro Data. El resultado se puede ver en el tablero principal. Por lo tanto, es posible realizar análisis de puertos en hosts locales e intranet.
TheHive Project Cortex versions 2.1.3 and below suffer from a server-side request forgery vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-08 CVE Reserved
- 2019-05-09 CVE Published
- 2019-05-10 First Exploit
- 2024-06-25 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/152804/TheHive-Project-Cortex-2.1.3-Server-Side-Request-Forgery.html | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46820 | 2019-05-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://blog.thehive-project.org/2019/02/11/unshortenlink-ssrf-and-cortex-analyzers-1-15-2 | 2019-05-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Thehive-project Search vendor "Thehive-project" | Cortex-analyzers Search vendor "Thehive-project" for product "Cortex-analyzers" | < 1.15.2 Search vendor "Thehive-project" for product "Cortex-analyzers" and version " < 1.15.2" | - |
Affected
|