CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
70.5%
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
Vendor | Product | Version | CPE |
---|---|---|---|
ikiwiki | ikiwiki | * | cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:* |
ikiwiki | ikiwiki | 3.20180105 | cpe:2.3:a:ikiwiki:ikiwiki:3.20180105:*:*:*:*:*:*:* |
ikiwiki | ikiwiki | 3.20180228 | cpe:2.3:a:ikiwiki:ikiwiki:3.20180228:*:*:*:*:*:*:* |
ikiwiki | ikiwiki | 3.20180311 | cpe:2.3:a:ikiwiki:ikiwiki:3.20180311:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
70.5%