CVE-2021-27329: SSRF
Published Feb 18, 2021
·Updated
Friendica 2021.01 allows SSRF via parseurl?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
Affected Software
1 affected component
Frendi Frendica=2021.01
Event History
Feb 18, 2021
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-27329?
CVE-2021-27329 is considered a medium severity vulnerability due to its potential for SSRF attacks.
2
How do I fix CVE-2021-27329?
To fix CVE-2021-27329, upgrade to the latest version of Friendica that addresses this vulnerability.
3
What is the impact of CVE-2021-27329?
CVE-2021-27329 can allow attackers to perform unauthorized DNS lookups or HTTP requests to arbitrary domains.
4
Which versions of Friendica are affected by CVE-2021-27329?
Only Friendica version 2021.01 is affected by CVE-2021-27329.
5
How can I identify exploitation attempts related to CVE-2021-27329?
Monitor your logs for unusual outgoing network requests or DNS lookups that reference unexpected domains.