Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-37940
HistoryDec 07, 2021 - 7:15 p.m.

Server side request forgery (ssrf)

2021-12-0719:15:00
PRIOn knowledge base
www.prio-n.com
4

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.

CPENameOperatorVersion
enterprise_searchlt7.16.0

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Related for PRION:CVE-2021-37940