CVE-2021-31828

Beschreibung:
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin’s intended scope.

CWE: CWE-94

CVSS-Bewertung
CVSS 2: HIGH – 7.5 (Version: 2.0)
CVSS 3: CRITICAL – 9.8 (Version: 3.1)

Links:

NVD – CVE-2021-31828
CVE – CVE-2021-31828

Link (max. 20) Quelle Tags
https://github.com/opendistro-for-elasticsearch/alerting/pull/353 CONFIRM Exploit Third Party Advisory
https://opendistro.github.io/for-elasticsearch-docs/version-history/ MISC Release Notes Vendor Advisory
https://play.google.com/store/apps/details?id=com.coolkit&hl=en_US MISC Exploit Third Party Advisory

Quelle: NVD – CVE-2021-31828
Datum Veröffentlichung: 2021-05-06T19:15Z, Datum letzte Änderung: 2021-05-07T09:31Z