CVE-2017-14611: SSRF
Published Apr 10, 2018
·Updated
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetchurlcontents component.
Affected Software
1 affected component
Agentejo Cockpit=0.13.0
Event History
Apr 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-14611.
2
What is the severity of CVE-2017-14611?
The severity of CVE-2017-14611 is critical with a CVSS score of 9.1.
3
What is the description of CVE-2017-14611?
CVE-2017-14611 is an SSRF (Server Side Request Forgery) vulnerability in Cockpit 0.13.0 that allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter.
4
Which software version is affected by CVE-2017-14611?
Cockpit version 0.13.0 is affected by CVE-2017-14611.
5
How can I fix CVE-2017-14611?
To fix CVE-2017-14611, upgrade to a version of Cockpit that is not affected by this vulnerability.