CVE-2018-7667: SSRF
Impact All users are affected.
Patches Unsuccessfully patched by 0fae40fb, included in version 4.4.0. Patched by 35bfaa75, included in version 4.7.8.
Workarounds Protect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin.
References http://hyp3rlinx.altervista.org/advisories/ADMINER-UNAUTHENTICATED-SERVER-SIDE-REQUEST-FORGERY.txt https://sourceforge.net/p/adminer/bugs-and-features/769/ https://gusralph.info/adminer-ssrf-bypass-cve-2018-7667/ (CVE-2020-28654)
For more information If you have any questions or comments about this advisory: Comment at 35bfaa75.
Other sources
Adminer through 4.3.1 has SSRF via the server parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/vrana/adminerto a version that resolves this vulnerability.Fixed in 4.7.8 - Upgrade
Upgrade
adminerto a version that resolves this vulnerability.Fixed in 4.7.8Patch 35bfaa75 - Compensating control
Protect access to Adminer also by other means, e.g. by HTTP password, IP address limiting, or by OTP plugin.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7667?
CVE-2018-7667 is classified as a critical vulnerability affecting all users.
How do I fix CVE-2018-7667?
To fix CVE-2018-7667, upgrade to version 4.7.8 of Adminer or later.
Which versions of Adminer are affected by CVE-2018-7667?
CVE-2018-7667 affects all versions of Adminer up to and including 4.3.1.
Is there a workaround for CVE-2018-7667?
No specific workarounds are recommended for CVE-2018-7667, so upgrading is advised.
What type of vulnerability is CVE-2018-7667?
CVE-2018-7667 is categorized as an unauthenticated server-side request forgery vulnerability.