← back
CVE-2021-37940

CVE-2021-37940

EPSS 0.8%CWE-918
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
07 Dec 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →