CVE-2021-33581: SSRF
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33581?
CVE-2021-33581 is a SSRF vulnerability in MashZone NextGen that allows an attacker to interact with arbitrary TCP services.
How does CVE-2021-33581 work?
CVE-2021-33581 works by abusing the feature to check the availability of a PPM connection in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.
What is the severity of CVE-2021-33581?
CVE-2021-33581 has a severity rating of 7.2 (High).
Which software is affected by CVE-2021-33581?
MashZone NextGen versions up to and including 10.7 GA are affected by CVE-2021-33581.
How can I fix CVE-2021-33581?
To fix CVE-2021-33581, it is recommended to update to a version of MashZone NextGen that is not affected by the vulnerability.