CVE-2024-22873: SSRF
Published Feb 26, 2024
·Updated
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.
Affected Software
2 affected components
Tencent Blueking CMDB>=3.2.x<3.9.x
Tencent Blueking Configuration Management Database>=3.2.2<=3.9.47
Event History
Feb 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:27 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22873?
CVE-2024-22873 is classified as a high severity vulnerability due to the potential for unauthorized access to internal systems.
2
How do I fix CVE-2024-22873?
To remediate CVE-2024-22873, update Tencent Blueking CMDB to the latest version that addresses the SSRF vulnerability.
3
Which versions of Tencent Blueking CMDB are affected by CVE-2024-22873?
CVE-2024-22873 affects Tencent Blueking CMDB versions from 3.2.x to 3.9.x.
4
What type of vulnerability is CVE-2024-22873?
CVE-2024-22873 is a Server-Side Request Forgery (SSRF) vulnerability.
5
Can CVE-2024-22873 be exploited remotely?
Yes, CVE-2024-22873 can be exploited remotely through crafted POST requests.