CVE-2021-41792: SSRF
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41792?
The severity of CVE-2021-41792 is medium with a CVSS score of 5.3.
What is the affected software for CVE-2021-41792?
The affected software for CVE-2021-41792 is Alfresco Content Services versions 5.0.0.0 to 5.2.7.11, 6.0.0.0 to 6.0.1.9, 6.1.1.0 to 6.1.1.10, and 6.2.0.0 to 6.2.2.18, and Alfresco Transform Services version 1.3.
How does CVE-2021-41792 work?
CVE-2021-41792 is triggered by uploading a crafted HTML file that can trigger an unexpected request by the transformation engine.
What is the fix for CVE-2021-41792?
To fix CVE-2021-41792, it is recommended to upgrade to the patched versions of Alfresco Content Services and Alfresco Transform Services.
Are there any references for CVE-2021-41792?
Yes, you can find more information about CVE-2021-41792 in the following references: [1] [2].