CVE-2021-1627: SSRF
Published Mar 26, 2021
·Updated
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.
Affected Software
1 affected component
Salesforce Mule>=3.8.0<=4.2.2
Event History
Mar 26, 2021
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-1627?
The severity of CVE-2021-1627 is critical with a CVSS score of 9.8.
2
Which versions of Mule runtime are affected by CVE-2021-1627?
Versions Mule 3.8.x, 3.9.x, and 4.x released before February 2, 2021, are affected by CVE-2021-1627.
3
What type of vulnerability is CVE-2021-1627?
CVE-2021-1627 is a Server Side Request Forgery vulnerability.
4
How does CVE-2021-1627 impact customers?
CVE-2021-1627 may affect both CloudHub and on-premise MuleSoft customers.
5
Is there a reference for CVE-2021-1627 for more information?
Yes, you can find more information about CVE-2021-1627 at the provided Salesforce reference link.