CVE-2014-9302: SSRF
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9302?
CVE-2014-9302 is classified as a high severity vulnerability due to its potential for exploitation via server-side request forgery.
How can I fix CVE-2014-9302?
To fix CVE-2014-9302, upgrade to Alfresco Community Edition version 5.0.b or later where the vulnerability has been patched.
Which versions of Alfresco are affected by CVE-2014-9302?
CVE-2014-9302 affects Alfresco Community Edition versions up to and including 5.0.a.
What type of vulnerability is CVE-2014-9302?
CVE-2014-9302 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2014-9302 lead to unauthorized access?
Yes, CVE-2014-9302 can potentially allow remote attackers to trigger unauthorized outbound requests.