The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2017:2674 | |
https://access.redhat.com/errata/RHSA-2017:2675 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1478792 | Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-09-28T20:00:00
Updated: 2017-12-30T10:57:01
Reserved: 2017-04-05T00:00:00
Link: CVE-2017-7553
JSON object: View
NVD Information
Status : Modified
Published: 2017-09-29T01:34:50.407
Modified: 2023-02-12T23:31:13.843
Link: CVE-2017-7553
JSON object: View
Redhat Information
No data.
CWE