CVE-2023-45152
CVSS V2 None
CVSS V3 None
Description
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.
Overview
- CVE ID
- CVE-2023-45152
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-10-16T23:34:28.735Z
- Last Modified Date
- 2023-10-16T23:34:28.735Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/engelsystem/engelsystem/security/advisories/GHSA-jj9g-75wf-6ppf | x_refsource_CONFIRM |
https://github.com/engelsystem/engelsystem/commit/ee7d30b33935ea001705f438fec8ffd05734f295 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-45152 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45152 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 10:14:42 | Added to TrackCVE |