CVE-2019-18355: SSRF
Published Oct 23, 2019
·Updated
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
Affected Software
1 affected component
Thycotic Secret Server<10.7.000000
Event History
Oct 23, 2019
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-18355?
CVE-2019-18355 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2019-18355?
To fix CVE-2019-18355, upgrade Thycotic Secret Server to version 10.7 or later.
3
What type of vulnerability is CVE-2019-18355?
CVE-2019-18355 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
4
What is affected by CVE-2019-18355?
CVE-2019-18355 affects the legacy Web launcher in Thycotic Secret Server versions before 10.7.
5
Can CVE-2019-18355 lead to unauthorized access?
Yes, CVE-2019-18355 could potentially lead to unauthorized access to internal resources.