漏洞描述
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/renmizo/CVE-2022-41412↗hackerone.comhttps://hackerone.com/reports/2445802↗github.comhttps://github.com/perfsonar/graphs/commit/463e1d9dc30782d9b1c002143551ec78b74e03bb↗www.perfsonar.nethttps://www.perfsonar.net/releasenotes-2022-09-20-4-4-5.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/170069/perfSONAR-4.4.4-Open-Proxy-Relay.html↗