CVE-2017-8794: SSRF
An issue was discovered on Accellion FTA devices before FTA912180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8794?
CVE-2017-8794 is classified as a critical vulnerability due to its potential to allow SSRF attacks.
How do I fix CVE-2017-8794?
To remediate CVE-2017-8794, upgrade the Accellion FTA devices to version FTA_9_12_180 or later.
What type of attack is possible with CVE-2017-8794?
CVE-2017-8794 allows for server-side request forgery (SSRF) attacks that could expose sensitive server files.
What versions of Accellion FTA are affected by CVE-2017-8794?
All versions of Accellion FTA devices prior to FTA_9_12_180 are affected by CVE-2017-8794.
What impact does CVE-2017-8794 have on data security?
CVE-2017-8794 can lead to unauthorized access to sensitive data on the server by exploiting improper URL validation.