CVE-2017-7200
⚪ Do wiadomości
Problem SSRF w OpenStack Glance umożliwia atakującym skanowanie portów sieci wewnętrznej.
CVSS
5.8
EPSS
2.1%
Exploit
none
Vendor
openstack
Opis źródłowy (NVD)
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.
ssrf
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 2.1% |
| Opublikowano (NVD) | 2017-03-21 06:59:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-17 13:59:34 UTC |
Referencje
- http://www.securityfocus.com/bid/96988 ([email protected]) [Third Party Advisory, VDB Entry]
- https://bugs.launchpad.net/ossn/+bug/1153614 ([email protected]) [Third Party Advisory]
- https://bugs.launchpad.net/ossn/+bug/1606495 ([email protected]) [Third Party Advisory]
- https://wiki.openstack.org/wiki/OSSN/OSSN-0078 ([email protected]) [Vendor Advisory]