2024-08-15 20:03:18 +00:00
{
"id" : "CVE-2024-22217" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-08-15T18:15:19.090" ,
2024-09-11 14:03:39 +00:00
"lastModified" : "2024-09-11T13:19:55.950" ,
"vulnStatus" : "Analyzed" ,
2024-08-15 20:03:18 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on."
2024-08-18 02:03:12 +00:00
} ,
{
"lang" : "es" ,
"value" : " Una vulnerabilidad de Server-Side Request Forgery (SSRF) en Terminalfour anterior a 8.3.19 permite a los usuarios autenticados utilizar funciones espec\u00edficas para acceder a servicios internos, incluida informaci\u00f3n confidencial en el servidor en el que se ejecuta Terminalfour."
2024-08-15 20:03:18 +00:00
}
] ,
2024-09-11 14:03:39 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-918"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "8.3.19" ,
"matchCriteriaId" : "5FEFBB62-F321-41DE-9209-56928DCEF596"
}
]
}
]
}
] ,
2024-08-15 20:03:18 +00:00
"references" : [
{
"url" : "https://docs.terminalfour.com/articles/release-notes-highlights/" ,
2024-09-11 14:03:39 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
2024-08-15 20:03:18 +00:00
} ,
{
"url" : "https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22217/" ,
2024-09-11 14:03:39 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Release Notes"
]
2024-08-15 20:03:18 +00:00
}
]
}