First published: Tue Feb 15 2022(Updated: )
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HelpSystems Cobalt Strike | <4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-23317 is high, with a severity value of 7.5.
The vulnerability in CobaltStrike <=4.5 is that the HTTP(S) listener does not determine whether the request URL begins with '/'.
Attackers can exploit CVE-2022-23317 by specifying the URL and obtaining relevant information.
The affected software for CVE-2022-23317 is HelpSystems Cobalt Strike version up to exclusive 4.5.
Yes, a fix is available for CVE-2022-23317. It is recommended to update to a version higher than 4.5.