CVE-2021-21009
Server-side request forgery (SSRF) in Campaign Classic could lead to sensitive information disclosure
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.6EPSS 3.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 ene 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Productos afectados
Adobe · Campaign¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →