CVE-2022-25801: SSRF
Published Jul 14, 2022
·Updated
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
Affected Software
2 affected components
bestpractical Request Tracker For Incident Response<4.0.3
bestpractical Request Tracker For Incident Response>=5.0.0<5.0.3
Remediation
Patch Available
Patch Available
Event History
Jul 14, 2022
CVE Published
via MITRE·11:44 AM
Data Sourced
via MITRE·11:44 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-25801.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.'
3
What is the severity of CVE-2022-25801?
The severity of CVE-2022-25801 is critical with a CVSS score of 9.1.
4
What software is affected by CVE-2022-25801?
Best Practical RT for Incident Response (RTIR) versions before 4.0.3 and 5.x before 5.0.3 are affected.
5
How can I fix CVE-2022-25801?
Update Best Practical RT for Incident Response (RTIR) to version 4.0.3 or 5.0.3.