CVE-2022-26499
Summary
| CVE | CVE-2022-26499 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-15 05:15:00 UTC |
| Updated | 2023-02-02 18:47:00 UTC |
| Description | An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181225 Debian Security Update for asterisk (DLA 3194-1)
- 181237 Debian Security Update for asterisk (DSA 5285-1)
- 502207 Alpine Linux Security Update for asterisk
- 503867 Alpine Linux Security Update for asterisk
- 690843 Free Berkeley Software Distribution (FreeBSD) Security Update for asterisk (8838abf0-bc47-11ec-b516-0897988a1c07)