CVE-2023-46236: FOG SSRF via unauthenticated endpoint(s)
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme. This also allows remote access to files visible to the Apache user group. Other impacts vary based on server configuration. Version 1.5.10 contains a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-46236?
CVE-2023-46236 is a server-side-request-forgery (SSRF) vulnerability in FOG.
How does the SSRF vulnerability in FOG work?
The SSRF vulnerability in FOG allows an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme.
What is the severity of CVE-2023-46236?
The severity of CVE-2023-46236 is high with a CVSS score of 8.6.
How can I fix CVE-2023-46236?
To fix CVE-2023-46236, upgrade to version 1.5.10 or newer of FOG.
Where can I find more information about CVE-2023-46236?
You can find more information about CVE-2023-46236 in the FOGProject advisory and commit links: - Advisory: [FOGProject Advisory](https://github.com/FOGProject/fogproject/security/advisories/GHSA-8qg4-9363-873h) - Commit: [GitHub Commit](https://github.com/FOGProject/fogproject/commit/9125f35ff649a3e7fd7771b1c8e5add3c726f763)