CVE-2017-7200

⚪ Do wiadomości

Problem SSRF w OpenStack Glance umożliwia atakującym skanowanie portów sieci wewnętrznej.

CVSS
5.8
EPSS
2.1%
Exploit
none
Vendor
openstack
Opis źródłowy (NVD)

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.

ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)2.1%
Opublikowano (NVD)2017-03-21 06:59:00 UTC
Ostatnia modyfikacja (NVD)2026-09-17 13:59:34 UTC
Referencje