Lucene search

K
nvd[email protected]NVD:CVE-2022-39039
HistoryJan 03, 2023 - 3:15 a.m.

CVE-2022-39039

2023-01-0303:15:09
CWE-918
web.nvd.nist.gov
1
enrich
a+hrd
url filtering
vulnerability
ssrf
remote attacker
http
https
request
system command
service disruption

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.004

Percentile

72.9%

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

Affected configurations

Nvd
Node
aenricha\+hrdMatch6.8
OR
aenricha\+hrdMatch7.0
VendorProductVersionCPE
aenricha\+hrd6.8cpe:2.3:a:aenrich:a\+hrd:6.8:*:*:*:*:*:*:*
aenricha\+hrd7.0cpe:2.3:a:aenrich:a\+hrd:7.0:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.004

Percentile

72.9%

Related for NVD:CVE-2022-39039