2024-12-08 03:06:42 +00:00

104 lines
3.0 KiB
JSON

{
"id": "CVE-2022-39039",
"sourceIdentifier": "twcert@cert.org.tw",
"published": "2023-01-03T03:15:09.610",
"lastModified": "2024-11-21T07:17:25.723",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "aEnrich\u2019s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service."
},
{
"lang": "es",
"value": "a+HRD de aEnrich tiene un filtrado inadecuado para par\u00e1metros de URL espec\u00edficos. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para enviar solicitudes HTTP arbitrarias para lanzar un ataque de Server-Side Request Forgery (SSRF), ejecutar comandos arbitrarios del sistema o interrumpir el servicio."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "twcert@cert.org.tw",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:aenrich:a\\+hrd:6.8:*:*:*:*:*:*:*",
"matchCriteriaId": "CFF0E4AE-57D2-4778-8E19-77F585F85EE2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:aenrich:a\\+hrd:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "E60AA81B-7D96-4771-902A-FACF58130D97"
}
]
}
]
}
],
"references": [
{
"url": "https://www.twcert.org.tw/tw/cp-132-6792-c4a62-1.html",
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-6792-c4a62-1.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}