← Retour aux CVEs
CVE-2023-25753
MEDIUM6.5
Description
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl parameter. Of particular concern is our ability to exert control over the HTTP method, cookies, IP address, and headers. This effectively grants us the capability to dispatch complete HTTP requests to hosts of our choosing. This issue affects Apache ShenYu: 2.5.1. Upgrade to Apache ShenYu 2.6.0 or apply patch https://github.com/apache/shenyu/pull/4776 .
Details CVE
Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie10/19/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
apache:shenyu
Faiblesses (CWE)
CWE-918CWE-918
References
https://lists.apache.org/thread/chprswxvb22z35vnoxv9tt3zknsm977d(security@apache.org)
https://lists.apache.org/thread/chprswxvb22z35vnoxv9tt3zknsm977d(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.