CVE-2017-14611
Summary
| CVE | CVE-2017-14611 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-10 15:29:00 UTC |
| Updated | 2022-08-18 19:44:00 UTC |
| Description | SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Agentejo | Cockpit | 0.13.0 | All | All | All |
| Application | Getcockpit | Cockpit | 0.13.0 | All | All | All |
| Application | Getcockpit | Cockpit | 0.13.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: SSRF(Server Side Request Forgery) in Cockpit CMS 0.13.0 (CVE-2017-14611) | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.